<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Papercut on CuraSec</title><link>https://curasec.metacog.co.kr/tags/papercut/</link><description>Recent content in Papercut on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 28 Aug 2026 21:21:40 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/papercut/index.xml" rel="self" type="application/rss+xml"/><item><title>PaperCut Chained RCE Flaws Actively Exploited, Emergency Patch Released</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-attackers-chain-two-papercut-flaws-to-execute-code-without-a/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-attackers-chain-two-papercut-flaws-to-execute-code-without-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Unauthenticated RCE via chained flaws in PaperCut NG/MF is being actively exploited; apply the emergency patch immediately and audit PaperCut server logs for unexpected Java process execution or outbound connections predating the patch.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of PaperCut print servers means assumed-breach posture is warranted — hunt for anomalous Java child processes or unusual network activity originating from PaperCut hosts since before the emergency patch date, and check EDR telemetry on any print-management systems.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> PaperCut NG/MF is common in enterprise and education environments; confirm with engineering that all instances are patched this week and verify no lateral movement occurred from print servers — prior PaperCut exploits (2023) drew board attention, so have a status update ready if asked.&lt;/li>
&lt;/ul></description></item><item><title>PaperCut NG/MF Zero-Day Actively Exploited, Emergency Patch Released</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-papercut-zero-day-exploited-in-attacks-affecting-all-ng-and/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-papercut-zero-day-exploited-in-attacks-affecting-all-ng-and/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> PaperCut NG and MF print management software is under active zero-day exploitation with confirmed customer incidents; apply PaperCut&amp;rsquo;s emergency patch for v25/v26 immediately and isolate unpatched instances from the network until patched.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Confirmed active exploitation means assume-breach posture for any PaperCut server in the estate; sweep PaperCut application logs for anomalous requests and lateral movement indicators since PaperCut servers have been used as initial-access footholds in prior ransomware campaigns.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Active zero-day with confirmed customer incidents in widely deployed enterprise print software; this week confirm whether your organization runs PaperCut NG or MF, verify emergency patching is underway, and prepare a brief for leadership if exposure is confirmed.&lt;/li>
&lt;/ul></description></item><item><title>PaperCut second emergency patch after initial fix bypassed in wild</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-papercut-releases-second-emergency-patch-for-exploited-flaws/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-papercut-releases-second-emergency-patch-for-exploited-flaws/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> PaperCut NG and MF are actively exploited and the first fix was bypassed, meaning unpatched and initially-patched instances remain at risk; update to the latest emergency release immediately and verify the new version is applied end-to-end.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Active exploitation with a bypassed patch means print servers in the estate may already be compromised; build or tune detections for anomalous outbound connections and process spawning from PaperCut service accounts, and sweep logs back to the original disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If PaperCut is in the environment, confirm with engineering that the second emergency patch is deployed and request a status update — active exploitation plus a failed first fix is the kind of event that can escalate to a breach if patching is delayed.&lt;/li>
&lt;/ul></description></item></channel></rss>