<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Recently patched PaperCut zero-days used in data theft attacks]]></title><description><![CDATA[<p dir="auto">Two security flaws in <strong>PaperCut NG</strong> and <strong>PaperCut MF</strong> — patched last week after being exploited in the wild — are now being leveraged in active data theft campaigns. The vulnerabilities, which were previously used as zero-days, allow attackers to gain unauthorized access to affected print management servers.</p>
<p dir="auto">The attacks reportedly follow a pattern where threat actors exploit the flaws to bypass authentication and execute arbitrary code. Once access is obtained, the attackers move laterally within the network to locate and exfiltrate sensitive documents, often targeting print queues and stored files. The print management software is widely deployed in enterprise environments, making these attacks particularly concerning for organizations that have not yet applied the updates.</p>
<ul>
<li><strong>Affected software:</strong> PaperCut NG and PaperCut MF</li>
<li><strong>Patches:</strong> Released last week by the vendor</li>
<li><strong>Attack vector:</strong> Exploitation of the zero-day flaws leads to remote code execution and unauthorized data access</li>
<li><strong>Observed activity:</strong> Post-exploitation actions include data theft, with no ransomware or destructive behavior confirmed so far</li>
</ul>
<p dir="auto">Administrators are strongly advised to verify that the latest patched versions are installed across all servers. In addition, monitoring print server logs for unusual login attempts or unexpected file access patterns is recommended. Network segmentation and restricting access to management interfaces can also reduce exposure.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks" target="_blank" rel="noopener noreferrer nofollow ugc">Unknown</a></p>
<p dir="auto">Has your organization already applied the latest PaperCut patches, or are you still assessing exposure to these zero-day exploits?</p>
]]></description><link>https://xploitlk.com/topic/176/recently-patched-papercut-zero-days-used-in-data-theft-attacks</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:29:35 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/176.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 01 Sep 2026 08:30:25 GMT</pubDate><ttl>60</ttl></channel></rss>