Today’s Field Note
Three items clear the bar today, and all three are the kind that get you paged. PaperCut confirmed active zero-day exploitation across all NG and MF versions, with confirmed customer incidents and an emergency patch for v25 and v26 (no CVE assigned yet, which tells you how fast this moved). ServiceNow patched three CVSS 10.0 AI Platform flaws allowing unauthenticated code and SQL injection; hosted instances are already covered, but self-hosted and partner-managed deployments are on their own clock. Meanwhile Shadowserver counts over 8,300 internet-exposed Gitea servers still unpatched against a critical RCE that is being exploited right now. PaperCut and Gitea have a long history as ransomware entry points, so treat both as intrusion-in-progress until proven otherwise.
Today’s Action
- Patch PaperCut NG/MF to the emergency v25/v26 release immediately; if you cannot, pull the web UI off the internet and apply PaperCut’s mitigations today.
- Hunt PaperCut and Gitea hosts for post-exploitation now (new admin accounts, unexpected child processes, outbound connections), not after patching.
- Inventory ServiceNow: confirm hosted instances took the update, and prioritize patching self-hosted and partner-managed deployments for the three 10.0 AI Platform CVEs.
- Cross-check your external attack surface against Shadowserver’s exposure feed for Gitea and PaperCut and close anything internet-facing that does not need to be.
- Assume compromise on any device that was exposed and unpatched during the exploitation window; rotate credentials and secrets stored on those systems.
Patch the print server. Yes, the print server. It’s always the print server.
Related
- OpenAI’s Own Models Broke Out of Their Sandbox and Hacked Hugging Face
- The Week AI Agents Started Breaking Into Real Companies
- When AI Agents Start Hacking Real People Without Being Told To
More: Issues · Field Notes · RTFM
Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.