PaperCut Zero-Day Under Active Attack: Emergency Patch Released
Brief
PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it.
PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details.
PaperCut issued emergency patches on Friday and urged customers to install them immediately. It also recommends disconnecting application servers from the internet and limiting access to trusted IP addresses.
“If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e. g. internal IP addresses).” states the advisory . “Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses.
All credited sources
Highest-trust first. Dates are the publisher's original publish time.
PaperCut Zero-Day Under Active Attack: Emergency Patch Released
PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it.
PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details.
PaperCut issued emergency patches on Friday and urged customers to install them immediately. It also recommends disconnecting application servers from the internet and limiting access to trusted IP addresses.
“If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e. g. internal IP addresses).” states the advisory . “Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses.
Take this action now, even if you have not observed suspicious activity.”
The company confirmed incidents affecting customers and said its investigation is still underway.
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.” reads the advisory . “We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing.
We will update this security bulletin as verified information becomes available, including indicators of compromise and remediation guidance.”
PaperCut has not yet disclosed details about the vulnerability, the attack method, or the attackers behind the campaign.
So far, the company has identified several indicators of compromise:
- Intrusion-detection, endpoint-security, or network-monitoring tools may flag suspicious activity involving the PaperCut Application Server, especially activity linked to pc-app.exe .
- Attackers may delete, truncate, or alter PaperCut server.log files to hide their activity.
PaperCut Zero-Day Under Active Attack: Emergency Patch Released
PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it.
PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details.
PaperCut issued emergency patches on Friday and urged customers to install them immediately. It also recommends disconnecting application servers from the internet and limiting access to trusted IP addresses.
“If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e. g. internal IP addresses).” states the advisory . “Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses.
Take this action now, even if you have not observed suspicious activity.”
The company confirmed incidents affecting customers and said its investigation is still underway.
“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.” reads the advisory . “We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing.
We will update this security bulletin as verified information becomes available, including indicators of compromise and remediation guidance.”
PaperCut has not yet disclosed details about the vulnerability, the attack method, or the attackers behind the campaign.
So far, the company has identified several indicators of compromise:
- Intrusion-detection, endpoint-security, or network-monitoring tools may flag suspicious activity involving the PaperCut Application Server, especially activity linked to pc-app.exe .
- Attackers may delete, truncate, or alter PaperCut server.log files to hide their activity.
