PAPERCUT Software has issued a warning about a zero-day vulnerability being actively exploited in its NG and MF print management solutions. Emergency patches have been released, and users are advised to implement them and restrict server access. The company is investigating confirmed incidents related to this vulnerability, without disclosing the attackers' identity. Indicators of compromise include a suspicious file named _pc-app.exe_ and altered _server.log_ files, which may suggest an intrusion.
This vulnerability is the latest in a series affecting PaperCut, with previous flaws being linked to ransomware attacks. Approximately 1,000 PaperCut instances are currently exposed to the internet.