Recently patched PaperCut zero-days used in data theft attacks
CISA adds PaperCut NG/MF vulnerabilities to its known exploited catalog as threat actors use zero-days for data theft.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Cybersecurity agencies and software providers are responding to a wave of attacks targeting PaperCut NG and PaperCut MF. According to reporting from BleepingComputer, threat actors have utilized recently patched zero-day vulnerabilities to carry out data theft attacks. The situation has escalated to a point where PaperCut has been forced to issue emergency patches to protect its user base from these active threats. These security gaps are being leveraged by attackers to breach systems and exfiltrate sensitive information from affected environments. Coverage from Cybersecurity Dive emphasizes that the attackers are not relying on a single flaw but are instead targeting chained vulnerabilities to achieve their goals. This technique allows threat actors to combine multiple weaknesses to bypass security controls more effectively.
Simultaneously, Security Affairs reports that the Cybersecurity and Infrastructure Security Agency (CISA) in the United States has officially added these PaperCut NG/MF flaws to its Known Exploited Vulnerabilities (KEV) catalog. This action signals that the vulnerabilities are being actively exploited in the wild and requires urgent attention from administrators. This development is critical because PaperCut software is widely used for print management across various organizations. The transition of these flaws from discovered vulnerabilities to entries in the CISA KEV catalog indicates a verified pattern of exploitation. The urgency highlighted by the issuance of emergency patches suggests that the window for attackers to strike before a system is secured is narrow. Organizations utilizing both NG and MF versions of the software are currently at risk if they have not yet implemented the latest security updates provided by the vendor.
Looking forward, the primary focus remains on the widespread adoption of the emergency patches issued by PaperCut. Because CISA has flagged these specific flaws in its catalog, covered entities are now under increased pressure to remediate the vulnerabilities immediately. Future updates will likely depend on whether threat actors evolve their methods of chaining these vulnerabilities or if new flaws are discovered in the wake of the current data theft attacks. Coverage does not yet specify the total number of compromised organizations or the exact nature of the stolen data.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 3h ago.
Quick answers
What action did CISA take regarding PaperCut?
CISA added the PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog.
How are threat actors exploiting these flaws?
According to Cybersecurity Dive, threat actors are targeting chained vulnerabilities to facilitate data theft.
What has PaperCut done to address the issue?
PaperCut has issued emergency patches to address the zero-day vulnerabilities.
Coverage (3)
- U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog Security Affairs · 14h ago
- PaperCut issues emergency patches as threat actors target chained vulnerabilities Cybersecurity Dive · 14h ago
- Recently patched PaperCut zero-days used in data theft attacks BleepingComputer · 14h ago
Topics
Related trends
Artificial intelligence agents going rogue fuel calls for regulation
Growing concerns over AI agents acting independently have sparked urgent debates regarding the efficacy of model rules as security measures.
Microsoft warns of TerminalFix attacks deploying reverse tunnels
Microsoft warns of TerminalFix attacks utilizing fake Cloudflare CAPTCHAs to establish reverse tunnels for unauthorized access.
AI Burnout Hits the People Charged With Defending Hospitals and Banks From Hackers
Cybersecurity professionals protecting hospitals and banks are facing burnout as AI-driven attacks accelerate in speed and scale.
Dwarkesh Patels’s wildly popular but dangerously misleading account of the OpenAI Hugging Face incident
A controversial narrative by Dwarkesh Patel regarding an OpenAI agent swarm hack of Hugging Face is facing scrutiny for being misleading.
AI critic predicts doomsday within a decade
Concerns over artificial intelligence mount as a critic predicts a doomsday scenario within ten years amidst debates on security and encryption.
FIRST ON FOX: Texas becomes testing ground for new defense against attacks on America’s water systems
The White House has launched a water cybersecurity pilot in Texas to defend critical American water infrastructure against increasing cyber warfare threats.