PaperCut Software is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company confirmed it has seen attacks against customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses. The urgent security advisory, published Thursday, says the security response team is investigating the active exploitation and treating the matter with the highest priority.
The vulnerability affects all versions of PaperCut NG and MF, but the company has not shared specific technical details about the flaw or the attack method. PaperCut stated that its security team reproduced the vulnerability using information provided by a University customer. Emergency patches have been released for customers with public-facing PaperCut NG and MF servers, with the company advising that this is for those unable to take other mitigating action.
PaperCut continues to recommend that customers with Application Servers exposed to the Internet use firewall rules or network access controls to restrict the web interfaces to trusted IP addresses. The company also shared indicators of compromise, including suspicious activity from the legitimate PaperCut pc-app.exe process and server.log files that have been modified, deleted, or are missing. Administrators should also look for specific errors in server.log, such as messages about a missing JDBC driver or a database error looking up a card ID. However, PaperCut warns that the absence of these indicators does not guarantee a server has not been compromised.
At this time, PaperCut has not disclosed who is behind the attacks, what attackers are doing after compromising servers, or whether data is being stolen. The company says it will continue updating its advisory with additional indicators of compromise and remediation guidance as its investigation proceeds. BleepingComputer contacted PaperCut with questions and will update its reporting when a response is received.
This is not the first time PaperCut has been targeted by threat actors after a security vulnerability was disclosed. In April 2023, attackers began exploiting the critical CVE-2023-27350 PaperCut vulnerability, which allowed unauthenticated attackers to bypass authentication and remotely execute code on vulnerable servers. Microsoft later linked some of those attacks to the Clop ransomware operation, which used vulnerable PaperCut servers for initial access to company networks, and also observed intrusions that led to LockBit ransomware attacks.
The 2023 exploitation spread to other groups, with Microsoft reporting that Iranian state-backed hacking groups were also exploiting the same flaw. In May 2023, CISA and the FBI issued a joint advisory warning that the Bl00dy Ransomware Gang was exploiting vulnerable PaperCut servers in attacks against the education sector. While PaperCut has a Print Archiving feature that can retain documents, Clop later told BleepingComputer it used the vulnerabilities for initial access rather than to steal archived documents directly from the servers.
More cybersecurity news from TechManNews.








