Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Summary
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.