PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of PaperCut NG and PaperCut MF in zero-day attacks, with confirmed incidents affecting customers. The company has released emergency patches and is urging organizations to restrict Internet-exposed PaperCut Application Servers to trusted IP addresses. #PaperCutNG #PaperCutMF
Keypoints
- PaperCut says a vulnerability in PaperCut NG and PaperCut MF is being actively exploited.
- Confirmed customer incidents have been reported in zero-day attacks.
- Organizations should restrict access to PaperCut web interfaces to trusted IP addresses.
- PaperCut has released emergency patches for public-facing servers.
- Indicators of compromise include suspicious pc-app.exe activity and altered or missing server.log files.