The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

PaperCut Emergency Patches Hit as Attackers Chain Flaws for Remote Code Execution

The Perimeter Desk
2026-08-29
# PaperCut Emergency Patches Hit as Attackers Chain Flaws for Remote Code Execution Listen up. It's Tuesday. In the world of incident response, Tuesday is usually when the wheels fall off. My inbox this morning looks like a digital crime scene, and if you’re feeling overwhelmed, you aren't alone. There have been 380 stories about data breaches this week alone. That's not a trend; it's a flood. Most of those reports are filler. They're written by people who think "cybersecurity" is a synonym for "magic." They use the word 'sophisticated' to describe an attack that was probably just a known CVE and a bit of patience. Whenever I see 'sophisticated' in a post-breach statement, I immediately assume the company forgot to patch a three-year-old vulnerability or left an S3 bucket open to the entire internet. It's a vanity word used to hide incompetence. I don't care who did it. I don't care if it was a nation-state or a teenager in a basement with a grudge. I care about the blast radius and whether you have a backup that actually works. Here is the mailbag for the week. *** **Gary, Des Moines: "I just spent a decent chunk of my budget on a new AI-driven security suite that promises to stop threats before they happen. Does this mean I can finally relax about our perimeter?"** Gary, I like your enthusiasm. I really do. But let me be the one to tell you this gently: no. You didn't buy a shield; you bought a very expensive alarm system that might occasionally tell you your house is on fire while you're standing in the flames. AI tools are great for filtering noise, but they aren't a substitute for basic hygiene. An AI suite won't save you if your admin is using 'Password123' or if you've got a critical vulnerability sitting on your gateway that's been public since 2021. Think of it like this. You can buy the fanciest biometric lock in the world for your front door, but if you leave the back window open and put a sign out front saying "Jewels Inside," the lock is irrelevant. Stop looking for a magic button. Go check your patch levels. That's where the real security happens. **Sarah, Manchester: "We use PaperCut for our print management across three offices. I saw the news about the emergency patches, but we're a small operation. Are these vulnerabilities really that dangerous if we aren't a huge target?"** Sarah, this is exactly how people get wrecked. You're thinking about "targets." Attackers don't think about targets; they think about vectors. They find a hole and they pour through it until they hit something worth stealing. PaperCut just released emergency patches for two critical vulnerabilities in their NG and MF software. These aren't just little glitches. Attackers are chaining these flaws together to get unauthenticated remote code execution. In plain English: they can run their own code on your server without needing a password. If you’re running an unpatched PaperCut server, you’ve essentially handed a key to your internal network to anyone with a scanner. Once they're in the print server, they aren't staying there. They'll move laterally into your file shares and your backups. I saw this play out during NotPetya back in 2017. It started with a niche piece of accounting software in Ukraine and ended up shutting down global shipping lanes because people trusted the "small" tools in their environment. What would this cost you on a Tuesday? If your print server becomes the beachhead for ransomware, you aren't just losing the ability to print PDFs. You're losing your entire operation. Patch it now. Not tomorrow. Now. **Marcus, Houston: "Cl0p is hitting Shell and GE through some PTC bug. As an IT manager for a mid-sized logistics firm, should I be worried about my vendors even if I'm patched?"** You should be terrified of your vendors. The Cl0p gang doesn't always kick down the front door; they find a side entrance through a trusted partner. This is the second-order effect that keeps me up at night. You can have the cleanest environment in Texas, but if you share data with a vendor who has a hole in their PTC software, your data is still out there. When giants like GE and Shell get hit, it's not just about their internal files. It's about the downstream ripple. Think about the insurers who now have to price in this risk, or the thousands of smaller suppliers whose contracts might be tied to those giants' uptime. If a major vendor goes dark, your supply chain doesn't just slow down—it snaps. Look at the Gitea situation. There are over 8,300 servers currently vulnerable to code execution attacks. That is 8,300 potential bridges into other networks. The criminals aren't looking for a single win; they're looking for a way to pivot. If you want to survive this, stop trusting the "certified" badge on your vendor's website. Ask them specifically how they are handling the recent wave of exploits. If they give you a vague answer about their 'robust security posture,' assume they're compromised and start planning your isolation strategy. *** CISA just added several entries to the Known Exploited Vulnerabilities list, including a Citrix NetScaler flaw (CVE-2026-8452) and an old Microsoft SQL Server RCE (CVE-2019-1068). For federal agencies, the deadline to patch those is today, August 29. I suspect half of them will miss it. We're also seeing a massive amount of sensitive data leaking from the edges. A UK airport operator just confirmed that 8.7 million customers had their data exposed. Then you've got millions of patients losing their DNA testing data. Once your DNA is on a leak site, you can't rotate your password. You can't change your biometric markers. That is a permanent loss of privacy. It makes the airport breach look like a rounding error. The common thread here isn't 'sophistication.' It's the failure to secure the boring stuff—the printers, the SQL servers, the airport Wi-Fi. Go check your printer server. I mean it.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. ShinyHunters claims McKesson data breach exposing 284 million patients - CyberInsider Google News Security
  2. PaperCut warns of hackers using printer management software flaw in attacks The Record
  3. UK airport operator confirms data breach affecting 8.7 million customers - SC Media UK Google News Security
  4. Millions of patients warned after DNA testing data breach - Cybernews Google News Security
  5. Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication The Hacker News
  6. Airport Wi-Fi Data Breach Exposes Millions of Travelers: This Week in Scams - McAfee Google News Security
  7. Data breach hits 8.7 million customers at UK airports - BetaNews Google News Security
  8. PaperCut releases second emergency patch for exploited flaws BleepingComputer

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.