Attackers Exploit PaperCut Servers to Install Remote Access
PaperCut confirms active exploitation of NG and MF servers. Release 3 patches the two-flaw chain; new log and service indicators help defenders investigate exposed hosts.
Read article →Reader view
Choose the default article length.
Page 4 of 10
PaperCut confirms active exploitation of NG and MF servers. Release 3 patches the two-flaw chain; new log and service indicators help defenders investigate exposed hosts.
Read article →StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →Shadowserver's retrospective Dysphoria report identifies about 296,000 compromised IoT devices and gives network owners evidence to locate and rebuild affected systems.
Read article →Five newly fixed WordPress flaws expose conditional paths to admin takeover or server code execution; defenders should verify six component versions and review AJAX and account activity.
Read article →A double-read type confusion lets guest JavaScript corrupt host memory; upgrade isolated-vm 6.x to 6.2.0 or 7.x to 7.0.1.
Read article →CISA says attackers are exploiting a Linux IPv6 kernel flaw that can give a local user root and, on affected RHEL 10 systems, escape a container.
Read article →Citrix documents denial of service. Separate research demonstrates a SAML path to root code execution but has not confirmed that it maps to this CVE.
Read article →An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.
Read article →ErrTraffic lures lead users to run Cruciferra, which uses a vulnerable signed driver to terminate security processes before the Remus stealer runs.
Read article →Next.js fixed two unauthenticated code-execution paths involving AVIF processing and Windows servers. Self-hosted operators need 15.5.24 or 16.3.3.
Read article →Dindoor uses the signed Deno runtime, encoded stages, and a pre-persistence sandbox check. Hunt the fixed process and registry sequence beneath the changing payload.
Read article →Gitea’s patch API can turn repository content into server code execution. Upgrade to 1.27.2 or later and check server activity for signs of compromise.
Read article →CareCloud says forensic review confirmed patient data exfiltration. HHS reports 3.76 million affected people, while public records do not map specific fields to each person.
Read article →CISA confirmed exploitation of a CVSS 10 Oracle WebLogic proxy flaw. Patch affected Apache and IIS plug-ins, then review requests for unauthorized data access.
Read article →A new Windows loader arrives through a fake Teams help desk; modules sent to Expel’s emulator phish passwords and tunnel into internal services.
Read article →An updated Android banking trojan blocks Google Play traffic, automates wireless ADB pairing, and targets 349 financial apps across 16 countries.
Read article →