THE report highlights critical cyber exploits tied to the BlueDelta group, associated with Russian state-sponsored espionage. Two main vulnerabilities in PaperCut NG/MF were identified: CVE-2026-82078, an unsafe reflection vulnerability, and CVE-2026-81578, a missing authentication issue. BlueDelta's recent campaigns target diplomatic and defense sectors in Europe using the HOOKEDGE malware, which spreads through macro-enabled Word documents.
The malware operates via a polling loop, using webhooks to communicate while masquerading as legitimate traffic. Recommendations for protection include blocking macros from internet documents and monitoring scheduled tasks for unusual activity.