PaperCut ZeroDay Exploited in Attacks, Affecting All NG and MF Versions
News Source : Internet
News Summary
- PaperCut has released an emergency patch for v25 and v26 to address the issue.
- Users who have PaperCut NG/MF Application Server exposed to the internet are advised to immediately restrict access to trusted IP addresses.
- In 2023, a critical flaw in PaperCut MF and NG ( CVE-2023-27350, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zeroday attacks.
Never miss a story from us, subscribe to our newsletter