If your office has a photocopier or a print room, odds are there is a quiet little piece of software sitting in the background keeping it all under control. For thousands of schools, hospitals, government offices and businesses, that software is PaperCut. And this week, PaperCut told the world that hackers have found a way in.
The company has issued an urgent security advisory after confirming active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF — the two versions most print managers actually run. In plain English: attackers are not just poking at this, they are already inside some systems. PaperCut said it is aware of “confirmed customer incidents” and is treating the matter with the highest priority.
Here is the scary part. The flaw lets an unauthenticated attacker take remote control of PaperCut’s trusted configuration. Security firm Huntress, which confirmed real-world attacks, explained that this can be used to “execute arbitrary Java code inside the application’s process.” Translation: a stranger on the internet could run any command they want on your print server, with no password, no alert, nothing.
What makes this bite harder is where PaperCut lives. It is not a side project. It monitors and controls Multi-Function Printers and office print devices across entire organisations. If that server is exposed to the public internet, it is a front door left wide open with a welcome mat.
PaperCut’s advisory is blunt about what to do: “If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only.” Use firewall rules, network access controls, whatever it takes — just make sure the server’s web interface cannot be reached from untrusted addresses. And do it now, “even if you have not observed suspicious activity.” Hope is not a security strategy.
For anyone who cannot quickly lock the server down, PaperCut has released an emergency patch for PaperCut NG/MF v25 and v26. Install it. But — and this is important — the patch mitigates the threat, it does not eliminate it. Huntress warns there may be more patches in the coming days, so keep watching PaperCut’s security bulletins page like a hawk.
How do you know if you have already been hit? PaperCut says to watch for alerts from intrusion-detection, endpoint-security or network-monitoring tools aimed at the PaperCut Application Server. Also look for missing, unexpectedly truncated, or deleted server.log files. But here is the catch they flag themselves: the absence of those signs is not proof you are clean.
Huntress proved the flaw could be used to fully compromise a server with the highest level of system access. Its advice to admins is layered: put the server behind a firewall, then go further — VLAN segmentation, VPN requirements, and a default policy of DENY to any machine or user that is not explicitly authorised. Treat the print server like the crown jewel it actually is.
There is a bigger lesson lurking here for the whole print industry. We love to talk about speed, colour and uptime. We rarely talk about the fact that a modern print environment is a networked computer infrastructure with valuable data flowing through it. A managed print fleet is now part of your attack surface, whether the procurement team realised it or not.
So this is the moment to ask the uncomfortable questions. Is our print server reachable from outside? Who actually monitors it? When did we last patch it? If the answer to any of those makes you uneasy, you are not alone — but you are also not safe. PaperCut’s response has been fast and transparent, which is exactly what you want from a vendor in a crisis. The rest is on us.
Source: Printweek — “PaperCut targeted by hackers”

中文

