Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch
Brief
PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution.
PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication remote code execution flaw is being actively exploited against real customers.
Researchers at Huntress found evidence of exploitation in two customer environments, and the security firm went further, reproducing the entire attack chain from scratch against a clean, unpatched install.
“Observed activity focused on system discovery. We have not observed secondary malware, further command-and-control traffic, or additional persistence or post-exploitation from the recovered payload.” reads the report published by Hutress.
