Find notable cyber news and cases, enriched with sources, timelines, and signals.

PaperCut emergency patches for public-facing NG/MF servers

Security Patch Release
First reported
Last updated
Happening score
H score 51
2 unique sources, 5 articles

Summary

Hide ▲

PaperCut says bad actors are actively exploiting a zero-day affecting PaperCut NG and PaperCut MF, with impact reported across all versions of the print management software. The company released an emergency patch for v25 and v26 and said it has confirmed customer incidents involving Internet-exposed PaperCut Application Servers. PaperCut also shared indicators of compromise, including suspicious activity from pc-app.exe and altered or missing server.log files, and told customers to restrict exposure with firewall rules or network access controls.

Related Happenings

PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave

Exploitation Wave
H score53 First: 05.09.2026 10:31 Last: 05.09.2026 10:31 Sources 1

About this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...

JFrog Artifactory CVE-2026-82329 exploitation wave

Exploitation Wave
H score56 First: 01.09.2026 20:53 Last: 01.09.2026 20:53 Sources 1

About this happening: Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administ...

PaperCut customer confirmed compromise incidents

Incident
H score41 First: 27.08.2026 19:31 Last: 27.08.2026 19:31 Sources 1

How related: PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.

About this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....

Latest development: 01.09.2026 10:48

Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).

Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India

Campaign
H score22 First: 12.08.2026 16:35 Last: 12.08.2026 16:35 Sources 1

About this happening: Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...

Latest development: 12.08.2026 18:38

Lazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.

Broadcom VMware vCenter active exploitation wave (CVE-2026-59310)

Exploitation Wave
H score48 First: 12.08.2026 12:01 Last: 12.08.2026 12:01 Sources 1

About this happening: Broadcom VMware vCenter is in an active exploitation wave centered on CVE-2026-59310, a CVSS 9.8 directory-traversal flaw that can enable arbitrary code executio...

Timeline

  1. 01.09.2026 10:48 1 articles · 9d ago

    PaperCut NG/MF zero-days abused for data theft

    Exploitation Observed

    Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against vulnerable PaperCut NG/MF print management servers to steal data, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th) and reporting an auth bypass used to hijack PaperCut's external user-lookup and dump DB tables via Derby.

    Show sources
  2. 27.08.2026 19:31 1 articles · 13d ago

    PaperCut warns of active zero-day exploitation in PaperCut NG and PaperCut MF

    Initial Disclosure

    PaperCut says it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF, warns that hackers are using zero-day attacks against all versions, and says it is aware of confirmed customer incidents involving Internet-exposed PaperCut Application Servers.

    Show sources
  3. 27.08.2026 19:31 5 articles · 13d ago

    PaperCut releases emergency patches for public-facing PaperCut NG/MF servers

    Mitigation Patch Update

    PaperCut releases emergency patches for customers with public-facing PaperCut NG/MF servers and tells administrators who cannot patch immediately to use firewall rules or network access controls to restrict web interfaces to trusted IP addresses.

    Show sources
  4. 27.08.2026 19:31 1 articles · 13d ago

    PaperCut shares indicators of compromise for suspected server compromise

    Detection Ioc Update

    PaperCut shares indicators of compromise for potentially compromised servers, including suspicious activity from the legitimate PaperCut pc-app.exe process, server.log files that have been modified, deleted, or are missing, and server.log errors such as 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST', while warning that a lack of indicators does not prove a server is clean.

    Show sources