← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI KEV ✓ (3 z 3) · ransomware EPSS 1.00 (nejvyšší)

AI-powered attack exploited PaperCut flaws to hack 395 organizations

A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]

Číst originál na BleepingComputer →

16 zpráv z 12 zdrojů · první 27. 8. 18:31 · poslední 10. 9. 17:55 CZ · EN/orig

PaperCut PaperCut Software veřejná správa školství výroba a průmysl US IT FI CA NL FR

tg: incident tg: varování tg: zneužíváno tg: zranitelnost tg: regulace tg: rozbor tp: malware tp: únik dat tp: AI

CVE v události 3

CVEhodnoceníKEVEPSS
CVE-2023-27350 9.8 3.0 · zdi KEV ✓ 1.00
CVE-2026-81578 8.8 4.0 · PaperCut KEV ✓ 0.03
CVE-2026-82078 9.4 4.0 · PaperCut KEV ✓ 0.04

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.4.

Text zpravodajského článku zmiňuje ještě chyby CVE-2021-42278, CVE-2021-42287, CVE-2023-2533. Tahle čísla radar vytáhl z textu článku, ne ze seznamu chyb, který zpráva uvádí, takže u nich neukazuje fakta z katalogů ani v tabulce výš; najdete je na stránkách těch CVE.

Jak se o tom psalo 16

  1. · BleepingComputer US nadpis události

    AI-powered attack exploited PaperCut flaws to hack 395 organizations

    A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]

  2. · GreyNoise Labs US

    Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

    11 organizations compromised in 26 seconds. GreyNoise breaks down the AI-enabled campaign against PaperCut that hit 440 instances across 48 countries.

  3. · BleepingComputer US

    Recently patched PaperCut zero-days used in data theft attacks

    Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]

  4. · CISA Advisories US

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…

  5. · CSIRT Itálie (ACN) IT

    PaperCut: rilevato sfruttamento in rete delle CVE-2026-82078 e CVE-2026-81578

    Rilevato lo sfruttamento attivo in rete delle vulnerabilità CVE-2026-82078 e CVE-2026-81578 – già sanate dal vendor – presenti nei prodotti PaperCut NG e PaperCut MF, soluzioni software per la gestione e il controllo delle stampe.

  6. · NCSC-FI FI

    URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)

    Classification: Critical, Solution: Temporary Fix, Exploit Maturity: High, CVSSv4.0: 9.4, CVEs: CVE-2026-82078, CVE-2026-81578, Summary: This advisory applies to all versions of: PaperCut NG PaperCut MF PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. Immediate action required: If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP…

  7. · BleepingComputer US

    PaperCut releases second emergency patch for exploited flaws

    PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]

  8. · The Record US

    PaperCut warns of hackers using printer management software flaw in attacks

    PaperCut released an emergency advisory on Thursday evening saying vulnerabilities in their print management software, PaperCut NG and MF, are under active exploitation.

  9. · Cyber Centre Kanada CA

    PaperCut security advisory (AV26-858)

    Serial number: AV26-858Date: August 28, 2026 As of August 27, 2026, PaperCut is affected by vulnerabilities in the following products: PaperCut MF Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 PaperCut NG Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 The Cyber Centre encourages users and administrators to review the provided web link and apply any…

  10. · NCSC-NL NL

    NCSC-2026-0334 [1.00] [M/H] Kwetsbaarheden verholpen in PaperCut MF en PaperCut NG van PaperCut

    PaperCut heeft kwetsbaarheden verholpen in PaperCut MF en PaperCut NG. Een ongeauthenticeerde kwaadwillende kan de kwetsbaarheden mogelijk achtereenvolgens misbruiken om een PaperCut-omgeving over te nemen en hierop willekeurige code uit te voeren. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar de kwetsbare PaperCut-omgeving te sturen.

  11. · Rapid7 US

    PaperCut NG/MF Critical Zero-Day Exploited in the Wild

    Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the time of writing, the vulnerability has not been assigned a CVE identifier, and PaperCut has not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details…

  12. · Huntress US

    PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE

    PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching and exposure guidance.

  13. · CISA KEV US

    PaperCut NG/MF Missing Authentication for Critical Function Vulnerability (CVE-2026-81578)

    CISA added CVE-2026-81578 to the Known Exploited Vulnerabilities catalog. Affected product: PaperCut NG/MF. Remediation due date: 2026-09-11.

  14. · CISA KEV US

    PaperCut NG/MF Unsafe Reflection Vulnerability (CVE-2026-82078)

    CISA added CVE-2026-82078 to the Known Exploited Vulnerabilities catalog. Affected product: PaperCut NG/MF. Remediation due date: 2026-09-11.

  15. · CERT-FR – avis FR

    Multiples vulnérabilités dans Papercut (28 août 2026)

    De multiples vulnérabilités ont été découvertes dans Papercut. Elles permettent à un attaquant de contourner l'authentification et d'exécuter du code arbitraire à distance. Papercut indique que ces vulnérabilités sont activement exploitées. L'éditeur explique que le correctif bloque les requêtes...

  16. · BleepingComputer US

    PaperCut warns of NG, MF flaw exploited in zero-day attacks

    PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]