Today’s Field Note

Three things worth your attention, all of them being exploited right now. PaperCut released a second emergency patch for NG and MF after researchers found multiple bypasses of the first fix; attackers are chaining two flaws to hit trusted configuration and run arbitrary Java without authentication. If you patched PaperCut last week, you are not done. Separately, a maximum-severity bug in the GiveWP WordPress donation plugin gives unauthenticated attackers command execution on the host, and CISA just added ownCloud CVE-2023-49105 (CVSS 9.8) to the KEV catalog after a Chinese-speaking actor used it to steal nuclear research data from a Philippine body. Old CVEs do not retire; they wait.

Today’s Action

  • Apply the latest PaperCut NG/MF emergency update immediately. The prior patch does not cover the known bypasses.
  • If PaperCut is internet-facing, pull it behind a VPN or IP allowlist now and review admin config for unauthorized changes.
  • Update the GiveWP plugin on every WordPress install, or disable it until you can. Scan hosts for signs of command execution.
  • Patch or decommission any ownCloud instance exposed to CVE-2023-49105; check WebDAV logs for phpinfo/pre-signed URL abuse.
  • Inventory these three across your estate before you assume you are unaffected. Assume exposed instances were already reached.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

The patch you shipped Friday is the bypass you read about Monday.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.