PaperCut warns of NG, MF flaw exploited in zero-day attacks
Reported exploitedPaperCutOur summary
PaperCut has issued an urgent advisory regarding the active exploitation of a zero-day vulnerability affecting all versions of PaperCut NG and PaperCut MF. The company confirms that customer servers are under attack and recommends immediately restricting internet exposure by limiting web interface access to trusted IP addresses. While specific technical details remain undisclosed, PaperCut has released an emergency patch for public-facing Application Servers and provided indicators of compromise, such as unusual activity in pc-app.exe processes, to help administrators detect potential breaches.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.