Archynetys Live news trend intelligence
▲ Peaking Technology

Recently patched PaperCut zero-days used in data theft attacks

Critical PaperCut zero‑days exploited in the wild have prompted emergency patches and a CISA alert, putting data theft at the forefront.

6sources
6articles
4velocity
+84%since first seen
14h agofirst detected

Evidence dossier

Intelligence passport

62/100 Strong
6distinct sources shown
15velocity measurements
1language editions checked
Unsupported statements were removed before publicationbrief evidence status

Measured timeline

  1. Detected The first matching coverage entered the Archynetys cluster.
  2. Latest coverage observed Most recent article currently attached to this story cluster.
  3. Peak measured velocity The recorded velocity reached 4.
  4. Evidence threshold reached The story had enough independent coverage for an explanatory brief.

Source diversity sample: SecurityWeek · quasa.io · Security Affairs · Rapid7 · Cybersecurity Dive · BleepingComputer.

How this dossier is built: methodology · AI policy · corrections.

Momentum

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The story so far

Rapid7 confirmed a critical zero‑day in use, while SecurityWeek described the exploitation escalating to active intrusions. The timing coincided with emergency patch releases, signalling an immediate threat to organizations using the software. Following the disclosures, the U.S.

Cybersecurity and Infrastructure Security Agency added the PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog, according to Security Affairs. quasa.io noted that emergency patches are available only for PaperCut versions 25 and 26, leaving earlier releases unprotected. Cybersecurity Dive reported that threat actors are chaining the vulnerabilities to steal data, and BleepingComputer confirmed that the newly patched zero‑days have already been used in data‑theft attacks. At present, organizations running unsupported PaperCut versions remain exposed, while those on 25 or 26 are urged to apply the emergency updates immediately.

Coverage indicates that the inclusion of the flaws in CISA’s catalog may drive broader remediation efforts across the sector. Monitoring for further exploitation attempts is advised as attackers have demonstrated the ability to combine the vulnerabilities for data exfiltration.

Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (89% supported) Updated 2h ago.

Who reported it (6)

The obvious questions

Which PaperCut versions are covered by the emergency patches?

Only versions 25 and 26, according to quasa.io.

Which agency added the PaperCut flaws to its Known Exploited Vulnerabilities catalog?

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), as reported by Security Affairs.

What type of attacks have been linked to the exploited zero‑days?

Data‑theft attacks, reported by BleepingComputer.

Topics

PaperCut Zero-Day CISA Data Theft Cybersecurity

Related trends

Open prediction lab

Can you beat the machine?

Pick tomorrow's top trend, then compare your result with Archynetys's self-graded forecast.

Make a prediction →