Recently patched PaperCut zero-days used in data theft attacks
Critical PaperCut zero‑days exploited in the wild have prompted emergency patches and a CISA alert, putting data theft at the forefront.
Evidence dossier
Intelligence passport
Measured timeline
- Detected The first matching coverage entered the Archynetys cluster.
- Latest coverage observed Most recent article currently attached to this story cluster.
- Peak measured velocity The recorded velocity reached 4.
- Evidence threshold reached The story had enough independent coverage for an explanatory brief.
Source diversity sample: SecurityWeek · quasa.io · Security Affairs · Rapid7 · Cybersecurity Dive · BleepingComputer.
How this dossier is built: methodology · AI policy · corrections.
Momentum
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The story so far
Rapid7 confirmed a critical zero‑day in use, while SecurityWeek described the exploitation escalating to active intrusions. The timing coincided with emergency patch releases, signalling an immediate threat to organizations using the software. Following the disclosures, the U.S.
Cybersecurity and Infrastructure Security Agency added the PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog, according to Security Affairs. quasa.io noted that emergency patches are available only for PaperCut versions 25 and 26, leaving earlier releases unprotected. Cybersecurity Dive reported that threat actors are chaining the vulnerabilities to steal data, and BleepingComputer confirmed that the newly patched zero‑days have already been used in data‑theft attacks. At present, organizations running unsupported PaperCut versions remain exposed, while those on 25 or 26 are urged to apply the emergency updates immediately.
Coverage indicates that the inclusion of the flaws in CISA’s catalog may drive broader remediation efforts across the sector. Monitoring for further exploitation attempts is advised as attackers have demonstrated the ability to combine the vulnerabilities for data exfiltration.
Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (89% supported) Updated 2h ago.
Who reported it (6)
- PaperCut Exploitation Escalates to Active Intrusions SecurityWeek · 1d ago
- PaperCut Zero-Day: Patches Only for Versions 25 and 26 quasa.io · 1d ago
- U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog Security Affairs · 1d ago
- PaperCut NG/MF Critical Zero-Day Exploited in the Wild Rapid7 · 1d ago
- PaperCut issues emergency patches as threat actors target chained vulnerabilities Cybersecurity Dive · 1d ago
- Recently patched PaperCut zero-days used in data theft attacks BleepingComputer · 1d ago
The obvious questions
Which PaperCut versions are covered by the emergency patches?
Only versions 25 and 26, according to quasa.io.
Which agency added the PaperCut flaws to its Known Exploited Vulnerabilities catalog?
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), as reported by Security Affairs.
What type of attacks have been linked to the exploited zero‑days?
Data‑theft attacks, reported by BleepingComputer.
Topics
Related trends
Palo Alto Networks beats quarterly estimates on AI demand, continues acquisition spree
Palo Alto Networks' stock surges as AI-driven cybersecurity demand fuels earnings beat and acquisition plans
AI Burnout Hits the People Charged With Defending Hospitals and Banks From Hackers
AI tools are accelerating cyber exploits, squeezing the staff defending hospitals and banks.
Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
Hackers claim 284 million patient records stolen from the nation’s largest drug distributor, sparking a health‑data breach wave.
AI critic predicts doomsday within a decade
AI's potential to enhance security is pitted against dire warnings of imminent catastrophe.
FIRST ON FOX: Texas becomes testing ground for new defense against attacks on America’s water systems
Texas is the first state to test a new federal cybersecurity program for water utilities.
Windows 11 is warning people that Defender Antivirus has been turned off, but don't worry, says Microsoft
A Windows 11 update (KB5121003) mistakenly flags Defender as disabled, prompting alerts that could erode user confidence in built‑in security.
Open prediction lab
Can you beat the machine?
Pick tomorrow's top trend, then compare your result with Archynetys's self-graded forecast.
📬 The daily trend digest
The world's top trends, once a day. No spam, one-click unsubscribe.