Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. Recently patched PaperCut zero-days used in data theft attacks

Recently patched PaperCut zero-days used in data theft attacks

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
1 Posts 1 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Two security flaws in PaperCut NG and PaperCut MF — patched last week after being exploited in the wild — are now being leveraged in active data theft campaigns. The vulnerabilities, which were previously used as zero-days, allow attackers to gain unauthorized access to affected print management servers.

    The attacks reportedly follow a pattern where threat actors exploit the flaws to bypass authentication and execute arbitrary code. Once access is obtained, the attackers move laterally within the network to locate and exfiltrate sensitive documents, often targeting print queues and stored files. The print management software is widely deployed in enterprise environments, making these attacks particularly concerning for organizations that have not yet applied the updates.

    • Affected software: PaperCut NG and PaperCut MF
    • Patches: Released last week by the vendor
    • Attack vector: Exploitation of the zero-day flaws leads to remote code execution and unauthorized data access
    • Observed activity: Post-exploitation actions include data theft, with no ransomware or destructive behavior confirmed so far

    Administrators are strongly advised to verify that the latest patched versions are installed across all servers. In addition, monitoring print server logs for unusual login attempts or unexpected file access patterns is recommended. Network segmentation and restricting access to management interfaces can also reduce exposure.

    Source: Unknown

    Has your organization already applied the latest PaperCut patches, or are you still assessing exposure to these zero-day exploits?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World