Two recently patched vulnerabilities in PaperCut NG and MF print management software are being actively exploited in data theft campaigns. The zero-days were patched last week after initial exploitation was discovered.
Security researchers have documented ongoing attacks leveraging the two PaperCut flaws, which affect widely-deployed print management systems used across enterprises and educational institutions.
The vulnerabilities allow attackers to bypass authentication and execute arbitrary code on vulnerable systems. Threat actors are using the exploits to gain network access and exfiltrate sensitive data from compromised organizations.
PaperCut released patches addressing the issues, but the window between disclosure and patch deployment has enabled attackers to establish footholds in multiple networks. Organizations running PaperCut NG and MF should prioritize applying the updates immediately.
Security teams should review logs for suspicious activity on print management systems dating back to before the patches were released. Indicators include unusual authentication attempts and unexpected administrative account creation on PaperCut servers.
The attacks underscore the persistent risk posed by zero-day exploits and the importance of rapid patching cycles for internet-facing and network-critical software.
Inexpensive GPS jamming devices are proliferating globally, disrupting navigation systems across civilian infrastructure. The low cost and easy availability of these tools are creating widespread interference zones.
Devices promising free movies are recruiting home internet connections into proxy networks without users' knowledge. The trade-off: your bandwidth and privacy.
QubesOS released a security update addressing a critical vulnerability that allows arbitrary code execution through an error reporting backchannel in the copy-to-VM function. The flaw affects multiple Qubes versions.
Android devices offer built-in protections against malicious apps, scam calls, and privacy breaches. Activating the correct security settings is essential to maximize these defenses.