Particle.news

PaperCut Zero-Day Actively Exploited, Company Issues Emergency Patch

Restrict web access to trusted IPs to cut the risk of remote compromise while PaperCut completes its investigation

Overview

  • PaperCut confirmed on Thursday that an unspecified vulnerability in all versions of PaperCut NG and PaperCut MF is being actively exploited and that it is aware of confirmed customer incidents.
  • The vendor reproduced the issue using data from a university customer and has published initial indicators of compromise, including suspicious activity by the legitimate pc-app.exe process and missing or altered server.log entries.
  • PaperCut released emergency patches for internet-facing Application Servers and advises organizations with public-facing servers to immediately restrict web access to trusted IP addresses or disconnect the server from the internet.
  • The company has not disclosed technical details of the flaw or named an attacker, and it says a lack of visible signs does not guarantee a server is uncompromised as the investigation continues.
  • This alert follows prior 2023 PaperCut flaws that were used to gain initial access for ransomware operations, which raises concern that compromised servers could be leveraged for broader network intrusion or ransomware attacks.