Attackers plant remote access tools on compromised PaperCut servers

The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools The vendor first warned of in-the-wild compromises on August 27, 2026, when it urged customers using the PaperCut NG and MF print management solutions to “immediately restrict web access to trusted IP addresses only.” At the time, … More →

This article has been indexed from Help Net Security

Read the original article: