PaperCut: zero-day under attack, emergency patch released
PaperCut Software has confirmed that a zero-day vulnerability in the NG and MF products has already been actively exploited in real-world attacks. The company has released an emergency patch and has asked customers to apply it immediately, even in the absence of obvious signs of compromise. Among the recommended measures are restricting access to application servers to trusted IPs only and removing direct exposure to the Internet. The company has not yet released full technical details or a CVE, a sign that analysis is still ongoing. The news is important because PaperCut is widely used for enterprise print management and a successful exploit could give attackers initial access to sensitive internal networks. The immediate mitigation guidance suggests that the operational risk is already concrete and rapidly evolving.
Source: Security Affairs


Leave a Reply