Tag

Papercut

All articles tagged with #papercut

PaperCut zero-days hit in the wild again, fueling data theft after patches
technology1 month ago

PaperCut zero-days hit in the wild again, fueling data theft after patches

Two newly patched PaperCut NG/MF flaws (CVE-2026-81578 and CVE-2026-82078) are being exploited to bypass authentication and remotely execute code, with attackers now dumping Derby DB tables to steal data. PaperCut released multiple emergency patches (including Release 3) and urges internet-facing servers to apply them; over 800 PaperCut servers are exposed online per Shadowserver. While attribution is unclear, this follows a history of targeted PaperCut exploits by ransomware and state-backed groups and underscores ongoing risk from misconfigured or exposed deployments.

PaperCut Flaw Chain Enables Unauthenticated Remote Code Execution, Prompting Emergency Patch
security1 month ago

PaperCut Flaw Chain Enables Unauthenticated Remote Code Execution, Prompting Emergency Patch

Hackers chained two PaperCut NG/MF flaws—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading)—to trigger unauthenticated remote code execution and alter server configuration; after an emergency patch with further hardening, exploitation appears limited but active, with attackers using Base64-encoded commands to identify the victim and a Java class to enumerate processes and files. Organizations should remove public exposure, apply the latest patches, and restrict access to trusted networks while monitoring logs for compromise indicators.

PaperCut rolls out second emergency patch to seal auth-bypass and RCE flaws
security1 month ago

PaperCut rolls out second emergency patch to seal auth-bypass and RCE flaws

PaperCut released Emergency Patch Release 2 to address two actively exploited flaws in NG/MF—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading leading to remote code execution). The update adds hardening beyond the first patch and is required for NG/MF 24–26; customers should upgrade (and restrict web interface access with firewalls) while investigators track post-exploitation activity and IOCs.

PaperCut Zero-Day Exploitation Forces Emergency Patch Across NG and MF
technology1 month ago

PaperCut Zero-Day Exploitation Forces Emergency Patch Across NG and MF

PaperCut warns that attackers are actively exploiting a zero-day flaw in all NG and MF versions, prompting an emergency patch for v25/v26 and ongoing investigation; security indicators include suspicious post-exploitation activity (pc-app.exe) and anomalous server.log entries, with guidance to restrict PaperCut access to trusted IPs; no details on the flaw or attackers yet, though a 2023 CVE was previously exploited by known threat actors.

Active zero-day exploit hits PaperCut NG/MF; emergency patches and access controls urged
security1 month ago

Active zero-day exploit hits PaperCut NG/MF; emergency patches and access controls urged

PaperCut warns a zero-day vulnerability affecting all PaperCut NG and MF versions is being actively exploited against customers with internet-facing servers. Emergency patches have been released, and admins are urged to restrict web interfaces to trusted IPs or via firewall rules. The advisory lists indicators of compromise such as unusual activity from pc-app.exe and changes to server.log, but warns that lack of indicators does not guarantee security as the investigation continues and no attacker details or data exfiltration specifics are disclosed.

Critical RCE Vulnerabilities Expose Unpatched Servers and MSMQ QueueJumper: Analysis
cybersecurity3 years ago

Critical RCE Vulnerabilities Expose Unpatched Servers and MSMQ QueueJumper: Analysis

PaperCut's NG/MF print management software has fixed a critical security vulnerability (CVE-2023-39143) that allows unauthenticated attackers to execute remote code on unpatched Windows servers. The flaw stems from two path traversal weaknesses, enabling threat actors to manipulate files on compromised systems. While the vulnerability only affects non-default server configurations, it is estimated that most PaperCut installations have the affected setting enabled. Admins are advised to install security updates promptly or restrict access through IP allowlisting. Previously, PaperCut servers were targeted by ransomware gangs exploiting other vulnerabilities, leading to data theft and attacks by state-backed hacking groups.

Bl00dy Ransomware Group Exploits PaperCut Vulnerability in Education Sector Attacks
cybersecurity3 years ago

Bl00dy Ransomware Group Exploits PaperCut Vulnerability in Education Sector Attacks

The FBI and CISA have issued a joint advisory warning that the Bl00dy Ransomware gang is exploiting a PaperCut remote-code execution vulnerability to gain initial access to networks, with a focus on the education sector. The vulnerability has been under active exploitation since at least April 18, 2023, and organizations have been slow to install the update, allowing exposure to attacks. The Bl00dy ransomware operation launched in May 2022 and uses an encryptor based on the leaked LockBit source code. The recommended action is to apply the available security updates on PaperCut MF and NG servers.