Source: BleepingComputer
Author: Sergiu Gatlan
URL: https://www.bleepingcomputer.com/news/security/cisa-flags-papercut-rce-bug-as-exploited-in-attacks-patch-now/
ONE SENTENCE SUMMARY:
CISA warns of active exploits targeting PaperCut software, urging immediate patching against vulnerabilities used by ransomware groups.
MAIN POINTS:
- CISA reports exploitation of a high-severity PaperCut NG/MF vulnerability allowing remote code execution.
- The software is used by over 100 million users in 70,000+ organizations worldwide.
- Vulnerability CVE-2023-2533 was patched in June 2023; exploitation requires a logged-in admin and a malicious link.
- CISA added this flaw to the Known Exploited Vulnerabilities Catalog, with a patch deadline of August 18 for U.S. agencies.
- All organizations, including private, are advised to prioritize patching this bug due to significant risks.
- Shadowserver tracks over 1,100 potentially exposed PaperCut servers, though not all are vulnerable.
- No evidence links CVE-2023-2533 to ransomware; similar exploits used in past breaches by ransomware gangs.
- Microsoft linked previous PaperCut attacks to LockBit, Clop ransomware, and Iranian state-backed groups.
- Previous breaches targeted the ‘Print Archiving’ feature to steal corporate data from compromised systems.
- Joint advisory from CISA and FBI warned educational organizations of potential exploitation by ransomware groups.
TAKEAWAYS:
- Immediate patching of PaperCut vulnerabilities is crucial to prevent potential exploitation.
- Organizations should prioritize addressing known exploited vulnerabilities to enhance security.
- Understanding the tactics used by ransomware gangs is essential for proactive defense.
- Collaborations between agencies like CISA, FBI, and companies like Microsoft help in threat mitigation.
- Continuous monitoring of exposed servers can prevent unauthorized access and data breaches.