← Back to Tech & Science

Threat Actors Exploit Patched PaperCut Vulnerabilities in Global Data Theft Campaign

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

LONDON (AP) — Unidentified threat actors are actively exploiting two recently patched security vulnerabilities in PaperCut NG and MF print management software to steal data from organizations worldwide. The attacks, detected on Sept. 1, target the widely used printing solution installed across more than 70,000 organizations serving approximately 100 million users globally.

The malicious activity involves the abuse of zero-day flaws that were addressed by security patches released in recent weeks. Despite the availability of fixes, attackers are leveraging these known weaknesses to gain unauthorized access to sensitive information within corporate networks. The software, which manages printing and copying functions for schools, universities, and businesses, serves as a critical entry point for these intrusions.

Security researchers have confirmed that the vulnerabilities allow remote code execution, enabling attackers to infiltrate systems without physical access to the devices. Once inside, the threat actors can exfiltrate confidential documents, user credentials, and other proprietary data stored on or routed through the print management infrastructure. The scope of the compromise remains under assessment as organizations scramble to verify whether their systems have been breached.

PaperCut MF, the primary product affected, is a staple in enterprise environments for tracking usage costs and enforcing security policies on printers and multifunction devices. The widespread adoption of the software means that a successful exploit can impact a vast array of industries simultaneously. While the specific identity of the threat actors remains unknown, the sophistication of the attacks suggests a coordinated effort aimed at high-value targets.

Network administrators are urged to immediately apply the latest security updates provided by the software vendor. The patches specifically address the two vulnerabilities currently being weaponized in the wild. Organizations that have not yet updated their systems face an elevated risk of data theft and potential ransomware deployment, as attackers often use initial access gained through print management flaws to move laterally across networks.

The timing of the attacks raises concerns about the speed at which threat actors are capitalizing on newly disclosed security flaws. With patches available for weeks, the continued exploitation indicates that many organizations have not yet completed their remediation efforts. This gap between patch availability and implementation leaves millions of users exposed to active cyber threats.

As investigations continue, several questions remain unanswered regarding the full extent of the data stolen and the specific objectives of the attackers. It is unclear whether the campaign is driven by financial motives, state-sponsored espionage, or other agendas. Additionally, security firms are monitoring for signs that the threat actors may be developing new techniques to bypass the recently issued patches.

The incident highlights the critical importance of timely software updates in maintaining the integrity of enterprise IT infrastructure. Until all affected systems are secured, the risk of further data breaches remains significant for organizations relying on PaperCut NG and MF solutions.

Discussion

0 / 2000