The development comes after PaperCut released a second emergency patch that it said includes “additional hardening beyond the original emergency patch.” The Australian company has yet to share details about the nature of the malicious activity weaponizing the flaws.
“At this time, we don’t have enough evidence to determine the threat actors’ ultimate end goal,” John Hammond, senior principal security researcher at Huntress, told The Hacker News. “Based on what we observed, the activity appears consistent with early-stage reconnaissance or validation, including commands to identify the victim’s user account and operating system.”
According to preemptive exposure management firm watchTowr, attackers are chaining together both vulnerabilities to bypass authentication and gain remote code execution on affected instances.
