Particle.news

PaperCut Zero-Days Escalate to Active Intrusions

Attackers are chaining an authentication bypass with unsafe Java class loading to run code and install remote‑access tools which raises urgent risk for internet‑exposed print servers.

Overview

  • Security firms and PaperCut disclosed late last week that two chained zero-day flaws let unauthenticated attackers bypass web management checks and load unsafe Java classes to achieve remote code execution.
  • PaperCut issued emergency patches and a hardened follow-up update after researchers found bypasses, and the vendor published indicators of compromise and response steps for affected branches.
  • Monitoring firms say the campaign has moved from short probes to hands-on-keyboard intrusions where attackers drop malicious .class files, delete logs and install legitimate remote-access software such as SimpleHelp and AnyDesk.
  • Large coverage gaps remain because many installs are older and unpatched, with researchers reporting roughly half of tracked PaperCut servers on versions lacking fixes and about 1,000 instances reachable on the public internet.
  • Responders advise restricting public access or isolating servers, preserving logs and forensic evidence before remediation, hunting for Derby log markers and unexpected services, and rebuilding any compromised Application Server from clean backups because exposed hosts should be assumed compromised.