← Back to Tech & Science

PaperCut Issues Security Updates to Halt Active Exploitation of Critical Flaws

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SYDNEY (AP) — PaperCut, a leading provider of print management software for educational institutions, released emergency security maintenance updates on Thursday to address two critical vulnerabilities currently being exploited in the wild. The patches replace earlier emergency fixes and are designed to stop active cyberattacks targeting school networks globally, with the U.S. education sector identified as the primary target.

The company announced the release at 7:45 a.m. UTC, stating that the updates resolve two distinct security flaws that have come under immediate exploitation by threat actors. The vulnerabilities allow attackers to gain unauthorized access to systems or execute malicious code, posing significant risks to the integrity of school data and network operations.

PaperCut confirmed that the new maintenance releases supersede previous emergency patches issued earlier in the week. The company emphasized that the initial fixes were insufficient to fully mitigate the evolving nature of the attacks, necessitating a more comprehensive update. Administrators using PaperCut's Print Management and Mobile Print solutions are urged to apply the latest updates immediately to secure their environments.

The exploitation of these flaws has been particularly aggressive against higher education institutions in the United States. While specific details regarding the threat actors or the full scope of the compromised networks were not disclosed, the timing and targeting suggest a coordinated campaign aimed at disrupting academic operations or harvesting sensitive student and faculty information.

Security experts note that print management systems are often overlooked in enterprise security strategies, making them attractive entry points for ransomware groups and data thieves. The active exploitation of these two flaws highlights a growing trend where attackers target niche software used heavily by schools to bypass traditional perimeter defenses.

PaperCut's update includes critical patches for its core server components and client applications. The company advised institutions to verify that all systems have been updated to the latest version available on their official download portal. Schools that have not yet applied the previous emergency patches are at heightened risk, as the new release contains additional safeguards against the specific attack vectors observed.

As of Thursday afternoon, it remains unclear how many institutions have already been compromised or if data exfiltration has occurred in connection with these vulnerabilities. PaperCut is working with affected organizations to assess the impact of the attacks and provide guidance on incident response. The company has not indicated whether further updates will be required as threat actors adapt their methods.

The situation underscores the urgent need for educational institutions to prioritize patch management across all software layers, including specialized tools like print servers that are integral to daily campus life but often lack the same level of scrutiny as core IT infrastructure.

Discussion

0 / 2000