Active zero-day exploit hits PaperCut NG/MF; emergency patches and access controls urged

TL;DR Summary
PaperCut warns a zero-day vulnerability affecting all PaperCut NG and MF versions is being actively exploited against customers with internet-facing servers. Emergency patches have been released, and admins are urged to restrict web interfaces to trusted IPs or via firewall rules. The advisory lists indicators of compromise such as unusual activity from pc-app.exe and changes to server.log, but warns that lack of indicators does not guarantee security as the investigation continues and no attacker details or data exfiltration specifics are disclosed.
- PaperCut warns of NG, MF flaw exploited in zero-day attacks BleepingComputer
- Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood The Register
- PaperCut Warns of Actively Exploited Vulnerability Affecting NG and MF Servers gbhackers.com
- Unknown PaperCut NG/MF vulnerability is under active attack Help Net Security
- PaperCut NG/MF Vulnerability Exploited in Active Attacks cyberpress.org
Reading Insights
Total Reads
0
Unique Readers
23
Time Saved
4 min
vs 5 min read
Condensed
90%
809 → 81 words
Want the full story? Read the original article
Read on BleepingComputer