• Menu
  • Skip to main content
  • Skip to primary sidebar

All Tech News

Latest Technology News

PaperCut Software Flaw Sparks Ransomware Attacks, CISA Warns

You are here: Home / Cyber Security News / PaperCut Software Flaw Sparks Ransomware Attacks, CISA Warns

The US Cybersecurity and Infrastructure Security Agency (CISA) has warned against a critical flaw found out in PaperCut application, which has now been connected to a collection of ransomware attacks.

The vulnerability (CVE-2023-27350) in PaperCut, a greatly adopted print administration alternative, has authorized cyber-criminals to remotely execute destructive code without the need of demanding any authentication credentials. 

For that reason, these attackers have efficiently deployed ransomware and illegally accessed delicate details.

Examine extra on this vulnerability in this article: Microsoft Blames Clop Affiliate for PaperCut Assaults

In reaction to the escalating threat, CISA and the Federal Bureau of Investigation (FBI) issued a cautionary advisory on Thursday urging end users to acquire rapid action to mitigate the risk.

“According to FBI noticed details, destructive actors exploited CVE-2023-27350 starting in mid-April 2023 and continuing by the current,” reads the technical compose-up.

In early Could 2023, the Education Amenities Subsector turned a primary target for the Bl00dy Ransomware Gang, as noted by the FBI. The group particularly aimed to exploit vulnerable PaperCut servers within just the Subsector, ensuing in information exfiltration, technique encryption and the issuance of ransom demands.

“The Bl00dy Ransomware Gang left ransom notes on victim methods demanding payment in trade for the decryption of encrypted information.”

The joint advisory provides detection procedures for the exploitation of CVE-2023-27350 as perfectly as indicators of compromise (IOCs) linked with Bl00dy Ransomware Gang activity. 

FBI and CISA strongly inspired customers and administrators to utilize patches immediately or workarounds if not able to patch. The agencies especially really encourage corporations that did not patch promptly to believe compromise and hunt for malicious action utilizing the detection signatures in the advisory. 

If opportunity compromise is detected, companies should use the incident reaction suggestions incorporated in the document.

Its publication will come a few of months following the FBI produced a assertion about a cyber-incident at a single of its highest-profile subject workplaces.

Some parts of this article are sourced from:
www.infosecurity-journal.com

Previous Post: « Toyota Admits Decade-Long Data Leak Affecting 2.15 Million Customers
Next Post: Essential Addons Plugin Flaw Exposes One Million WordPress Websites »

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Hackers Use Leaked Shellter Tool License to Spread Lumma Stealer and SectopRAT Malware
  • Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play
  • Malicious Pull Request Infects 6,000+ Developers via Vulnerable Ethcode VS Code Extension
  • 5 Ways Identity-based Attacks Are Breaching Retail
  • RondoDox Botnet Exploits Flaws in TBK DVRs and Four-Faith Routers to Launch DDoS Attacks

Copyright © 2025 · AllTech.News, All Rights Reserved.