PAPERCUT ZERO-DAY VULNERABILITY ACTIVELY EXPLOITED IN CYBERATTACKS

PaperCut is warning customers about a critical security vulnerability that attackers are actively exploiting in zero-day attacks targeting its PaperCut NG and PaperCut MF print management software. The vulnerability affects all versions of the products, according to the company.

PaperCut says it has confirmed incidents affecting customers and is treating the threat as a high priority. Emergency security patches have been released for versions 25 and 26, and organizations are urged to update affected systems as soon as possible.

Security teams should also investigate PaperCut servers for signs of compromise. Indicators of compromise (IOCs) identified by PaperCut include:

  • Suspicious activity involving the PaperCut Application Server, particularly post-exploitation behavior originating from pc-app.exe
  • Missing, deleted, or unexpectedly shortened server.log files
  • server.log entries containing ERROR No suitable driver found for jdbc\:no\:x
  • server.log entries containing ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

Because PaperCut software is commonly deployed within business, education, and government environments, compromised servers could provide attackers with an opportunity to establish a foothold inside organizational networks. Administrators should treat any unusual PaperCut server behavior as potentially suspicious and investigate affected systems for additional signs of unauthorized access.

Organizations running PaperCut NG or MF should prioritize patching while reviewing endpoint, network, and intrusion-detection alerts for suspicious activity. PaperCut’s investigation remains ongoing, meaning additional technical details and indicators could emerge as researchers learn more about the attacks.

Leave a Comment

Your email address will not be published. Required fields are marked *