Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Recently patched PaperCut zero-days used in data theft attacks

    September 1, 2026

    Five Venezuelans plead guilty to ATM jackpotting attacks in US

    September 1, 2026

    Microsoft says Windows 11 KB5120998 update resets mouse settings

    September 1, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Recently patched PaperCut zero-days used in data theft attacks
    News

    Recently patched PaperCut zero-days used in data theft attacks

    adminBy adminSeptember 1, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    PaperCit

    Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.

    According to PaperCut Software, the software is used by 100 million users across more than 70,000 organizations, including large companies, state agencies, and educational institutions.

    Tracked as CVE-2026-81578 and CVE-2026-82078, the two security flaws can be chained to bypass authentication and gain remote code execution on vulnerable PaperCut NG and MF print management servers.

    PaperCut Software released three sets of emergency patches to address the vulnerabilities on Thursday, Friday, and Tuesday, “to rush mitigations to customers who might not be able to remove their servers from the internet.”

    “The first release was an emergency mitigation. The next release added further hardening as we understood more,” explained PaperCut CEO Chris Dance today. “We have additional work in hand, and there may be further Emergency Patch releases if required, and of course, a final fully QA and regression-tested official release soon.”

    The company has also published indicators of compromise to help defenders block ongoing attacks, but it has yet to attribute the attacks or explain what the threat actors are doing after compromising vulnerable servers.

    “We recommend all customers with internet-facing Application Servers install Release 3 as soon as possible, even if they have already applied an earlier emergency release,” the company said.

    Actively exploited for data theft

    Over the weekend, threat intelligence company Defused also confirmed that attackers have begun abusing the two flaws in the wild to steal data from victims’ servers.

    “We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th),” Defused said. “An actor is abusing the auth bypass to hijack PaperCut’s external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft – dumping DB tables via Derby.”

    Internet security watchdog Shadowserver currently tracks over 800 PaperCut MF and NG servers exposed online, although there is no information on how many are honeypots or have already been secured against these attacks.

    PaperCut servers exposed online
    PaperCut servers exposed online (Shadowserver)

    ​Both state-backed hacking groups and ransomware gangs have previously targeted PaperCut security flaws in the wild over the last several years.

    A critical remote code execution vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351) were chained in April 2023 attacks linked to the LockBit and Clop ransomware gangs.

    Microsoft revealed two weeks later that the Muddywater and APT35 Iranian state-backed hacking groups had also joined the attacks.

    As the company explained at the time, the threat groups abused the ‘Print Archiving‘ feature designed to save all documents sent through PaperCut printing servers.

    One month later, in May 2023, the FBI and CISA warned that the Bl00dy Ransomware gang had also begun exploiting the CVE–2023–27350 flaw for initial access to targets’ networks.

    The Cybersecurity and Infrastructure Security Agency (CISA) flagged another remote code execution vulnerability (CVE-2023-2533) as actively exploited in July 2025.

    Update September 01, 07:27 EDT: Added info on Emergency Patch Release 3.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleFive Venezuelans plead guilty to ATM jackpotting attacks in US
    admin
    • Website

    Related Posts

    News

    Five Venezuelans plead guilty to ATM jackpotting attacks in US

    September 1, 2026
    News

    Microsoft says Windows 11 KB5120998 update resets mouse settings

    September 1, 2026
    News

    Financially Motivated Threat Actor BREEZE COMET Targets Brazil

    August 31, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    Recently patched PaperCut zero-days used in data theft attacks

    September 1, 2026

    Five Venezuelans plead guilty to ATM jackpotting attacks in US

    September 1, 2026

    Microsoft says Windows 11 KB5120998 update resets mouse settings

    September 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.