Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood

← Back to the feed

Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood

The Register · 4 hours ago

PaperCut has warned that its PaperCut NG and PaperCut MF print-management products are being actively exploited through a previously unknown vulnerability, after a university reported an attack. The issue matters because internet-exposed PaperCut web interfaces may give attackers a route further into affected organisations’ networks, and the company has confirmed customer incidents.

PaperCut has not disclosed the technical nature of the flaw, but possible signs of compromise include altered logs and alerts from intrusion-detection, endpoint-security and network-monitoring systems. Customers with publicly accessible servers are urged either to remove their web interfaces from the public internet and restrict access to trusted internal IP addresses, or apply an emergency patch that has not completed the company’s normal release process; a fully validated fix is still being prepared.

  • PaperCut confirms active exploitation of an undisclosed zero-day vulnerability.
  • Internet-facing PaperCut servers should be restricted or taken offline urgently.
  • An emergency patch exists but has not undergone normal validation.

Software

Read the full article at the source →