PaperCut has issued an urgent security advisory concerning a vulnerability affecting PaperCut NG and PaperCut MF print-management servers. The issue is particularly concerning because the vendor has confirmed that attackers are actively exploiting the vulnerability in real-world environments. Organizations operating PaperCut Application Servers with web interfaces accessible from the public internet should therefore consider the issue a high-priority security incident. The vulnerability can expose organizations to unauthorized access and potential post-exploitation activity on affected servers. PaperCut has confirmed customer incidents and worked with security and digital-forensics teams to reproduce the issue and develop emergency fixes. The immediate security priority is to remove public access to PaperCut Application Server interfaces. Administrators should use firewalls, network access controls, VPNs, or other perimeter protections to ensure that management interfaces are available only to trusted users and networks. PaperCut has released emergency updates for supported version 25 and 26 branches of both NG and MF. Organizations should apply the appropriate fixed release as quickly as possible, particularly where servers cannot be adequately isolated from the internet. Security teams should also investigate potentially compromised systems rather than assuming that patching alone resolves the incident. Analysts should review PaperCut logs, EDR alerts, authentication activity, network connections, and suspicious processes. Unexpected deletion or truncation of server log files may also warrant investigation. PaperCut has identified specific error messages that may assist threat hunting, although their absence does not confirm that a server is uncompromised. Organizations using external databases for Card/ID lookups should additionally review the impact of the update on existing SQL integrations.
Gyazo, the cloud-based screenshot and screen-recording platform operated by Helpfeel, confirmed a data breach after attackers exploited a server vulnerability on September 11, 2026...
Plugin4Shell is a high-severity supply-chain vulnerability affecting major AI coding agents, including Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. T...
A newly identified Windows malware framework dubbed MovieReaper is being distributed through compromised torrent infrastructure and fake downloads of popular movies. Security resea...