PaperCut warns of hackers using printer management software flaw in attacks
PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.
PaperCut, a print management software provider, is currently facing a zero-day attack that is causing significant concern for its customers. The vulnerability was discovered after university security teams alerted the company to an attack. PaperCut has released an emergency patch to address the issue, but it is not an official release and is intended for customers with public-facing PaperCut servers who are unable to take other mitigating actions.
The attack involves exploiting the web interface of the company's products, which can grant access to deeper parts of a user's network. Indicators of compromise include altered log files, as well as alerts from intrusion detection software, endpoint security tools, and network monitoring packages. The company has not disclosed the nature of the vulnerability to avoid giving attackers further insight into the flaw.
Users are advised to remove the web interface of their PaperCut servers from the public internet, allowing access only from trusted internal IP addresses. This is considered the most effective way to protect against the attack, although it may be challenging to implement due to the need for a change window in which to apply the emergency patch. The Register believes most users will opt for this solution, as the risks associated with running unvalidated emergency software are undesirable.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.