Today’s Field Note

Three items clear the bar today, and all three are the kind that get you paged. PaperCut confirmed active zero-day exploitation across all NG and MF versions, with confirmed customer incidents and an emergency patch for v25 and v26 (no CVE assigned yet, which tells you how fast this moved). ServiceNow patched three CVSS 10.0 AI Platform flaws allowing unauthenticated code and SQL injection; hosted instances are already covered, but self-hosted and partner-managed deployments are on their own clock. Meanwhile Shadowserver counts over 8,300 internet-exposed Gitea servers still unpatched against a critical RCE that is being exploited right now. PaperCut and Gitea have a long history as ransomware entry points, so treat both as intrusion-in-progress until proven otherwise.

Today’s Action

  • Patch PaperCut NG/MF to the emergency v25/v26 release immediately; if you cannot, pull the web UI off the internet and apply PaperCut’s mitigations today.
  • Hunt PaperCut and Gitea hosts for post-exploitation now (new admin accounts, unexpected child processes, outbound connections), not after patching.
  • Inventory ServiceNow: confirm hosted instances took the update, and prioritize patching self-hosted and partner-managed deployments for the three 10.0 AI Platform CVEs.
  • Cross-check your external attack surface against Shadowserver’s exposure feed for Gitea and PaperCut and close anything internet-facing that does not need to be.
  • Assume compromise on any device that was exposed and unpatched during the exploitation window; rotate credentials and secrets stored on those systems.

Patch the print server. Yes, the print server. It’s always the print server.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.