news.mlab.sh
Back to the feed
threat-intel

PaperCut warns of hackers using printer management software flaw in attacks

Critical
Summary

PaperCut, a popular printer management software provider, has warned customers of a serious vulnerability being actively exploited by cybercriminals. The vulnerability, affecting their PaperCut NG and MF software, has led to confirmed customer incidents and prompted the company to release multiple patches. Organizations using PaperCut are urged to take immediate steps to secure their systems, as the software is a common entry point for attackers, including ransomware groups and state-sponsored actors.

PaperCut has issued an emergency advisory warning customers about a critical vulnerability within their printer management software, PaperCut NG and MF, currently being exploited by cybercriminals. The company’s security response team is investigating active exploitation of the vulnerability. PaperCut’s software is widely used by large organizations, including universities, corporations, and governments, managing printers from brands like Canon, Epson, Xerox, and Brother.

PaperCut stated that it used information provided by a university’s security team to reproduce the vulnerability and develop a fix. Multiple cybersecurity companies, including Huntress, have confirmed evidence of exploitation targeting the bugs. The initial patch released by PaperCut was deemed insufficient, and a new patch was subsequently released on Friday, developed in collaboration with experts from Huntress and watchTowr.

Jake Knott, head of threat intelligence at watchTowr, noted that previous PaperCut vulnerabilities have been leveraged by ransomware gangs and opportunistic attackers to gain initial access into corporate environments. He emphasized that PaperCut’s software represents a ‘prime target’ due to its internet-facing nature and potential to store and exfiltrate sensitive printed documents.

In 2023, U.S. law enforcement agencies alerted K-12 schools to the risk posed by ransomware gangs like Bl00dy and Clop exploiting PaperCut bugs. The Cybersecurity and Infrastructure Security Agency (CISA) specifically issued an advisory for the education sector due to the heightened exposure. Microsoft also reported that an Iranian state-backed group exploited the same vulnerability in multiple attacks that year.

Read the full article at The Record