[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fD1uRQfaZxt9TfauNjqfvRujjDyOcahTG2z2jpIkHtFc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"fd424adc-c750-4aaa-a570-3e96d5164663","papercut-zero-days-chained-for-data-theft-before-patches-applied","efe4748d-4b2c-4a04-b251-28169c967d6c","PaperCut Zero-Days Chained for Data Theft Before Patches Applied","Attackers exploited two critical zero-day vulnerabilities in PaperCut print management software to bypass authentication, execute remote code, and exfiltrate database contents before patches were available. The chaining of these flaws demonstrates how sophisticated threat actors can combine vulnerabilities to maximize impact, moving beyond simple system compromise to targeted data theft. Print management software is often overlooked in security programs despite having broad network access and storing sensitive user and configuration data. This incident underscores that any internet-facing or internally accessible application — even peripheral management tools — must be included in vulnerability management and rapid patching programs.","**Immediate actions:**\n- Apply PaperCut's emergency patches immediately and verify patch integrity before deployment.\n- Isolate PaperCut servers from direct internet exposure and restrict access to trusted IP ranges only.\n- Review PaperCut logs and apply the published indicators of compromise (IoCs) to detect signs of exploitation.\n\n**Long-term improvements:**\n- Maintain a complete, up-to-date inventory of all applications — including peripheral management tools — to ensure none are excluded from patch cycles.\n- Implement a formal emergency\u002Fout-of-band patching procedure for critical vulnerabilities with CVSS scores above 9.0.\n- Enforce least-privilege access on print management systems so compromised accounts cannot access sensitive database tables.\n\n**Detection measures:**\n- Enable detailed authentication and API request logging on PaperCut servers and forward logs to a centralized SIEM.\n- Configure alerts for anomalous database query volumes or unexpected admin-level actions within print management platforms.\n- Deploy network-level monitoring to detect unusual outbound data transfers from print server infrastructure.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","CIS Control 3: Data Protection","CIS Control 13: Network Monitoring and Defense","NIST SP 800-40 Rev 4: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST AC-3: Access Enforcement","NIST AU-12: Audit Record Generation","NIST IR-4: Incident Handling","GDPR Article 32: Security of Processing","GDPR Article 33: Notification of a Personal Data Breach","ITIL: Change Management \u002F Emergency Change Process","published","2026-09-01T08:20:37.306852+00:00","2026-09-01T08:20:37.006+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Frecently-patched-papercut-zero-days-used-in-data-theft-attacks\u002F","recently-patched-papercut-zero-days-used-in-data-theft-attacks-6440af","Recently patched PaperCut zero-days used in data theft attacks",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":45,"name":46,"slug":47,"description":48,"color":49},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[51],{"id":52,"date":53,"edition":54,"title":55,"audio_url":56},"f6ec6c97-2a24-4cc7-970c-248f9a7f92ab","2026-09-01","afternoon","ThreatNoir Afternoon Brief — September 1","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-01\u002Fthreatnoir-afternoon-brief-2026-09-01.mp3"]