Security1 distinct publisher2 min readPublished
PaperCut confirms exploited customer incidents in NG and MF, publishes log strings to hunt for, and withholds the flaw itself, which leaves network reachability as the only control anyone can apply today.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Both log strings in the bulletin are database errors. One reports no suitable JDBC driver for `jdbc:no:x`; the other is a DatabaseUtils failure looking up cardID with a VALUES CAST [6]. Read literally, that points at the database layer of the Application Server rather than the print pipeline. PaperCut has not described a mechanism and says it will publish specific indicators of compromise once it pinpoints them [5], so that reading is artifacts, not root cause.
The item that shapes the hunt is the third one: missing, unexpectedly truncated, or deleted `server.log` files [6]. If the log is cleared, the two error strings go with it, and a negative result describes the log rather than the host. That is consistent with the vendor telling customers to restrict access to the Application Server even when they find nothing [7].
Scope is the part of this advisory that favours the defender. PaperCut describes the Application Server as the brain of both NG and MF, normally one per organization [4]. The network change is therefore a single-host job: one set of web interfaces to pull off the public internet using firewall rules or network access controls [7], not a rollout across copiers [11]. Most of the elapsed hours will go to establishing who currently reaches that interface from outside and what stops working when they cannot.
Exploitation is confirmed before any identifier exists [2], which means the usual keys do not work. No CVE, so no scanner signature, no KEV entry, no patch SLA. The asset question you can answer today is which host runs `pc-app.exe` and answers from an untrusted address [6].
In 2023 the same software was worked by affiliates of Clop and LockBit, using CVE-2023-27350 for remote code execution and CVE-2023-27351 for information disclosure [8]. Those came with identifiers and versions. What is public here is a bulletin dated Thursday 27 August [3][10], confirmed customer incidents treated at highest priority [2], and an instruction to restrict web access to trusted internal addresses [3]. What is not public: the CVE, the affected builds, a fix, the actor, and the size of the confirmed set [5]. No ransomware brand has been named, so any pairing of this flaw with the 2023 crews is inference.
PaperCut NG runs print management for offices and schools; MF adds direct integration with multifunction copiers from most major brands and is reachable from the device touchscreen [9]. Until affected versions are published, an internet-facing Application Server should be treated as reachable by whoever holds the exploit [1].
Ranked by verification strength, evidence, and original report placement.
The security bulletin was published on Thursday and its wording points to a remotely exploitable flaw: "If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses)."
PaperCut Software warned that a yet unspecified vulnerability affecting PaperCut NG and PaperCut MF is being exploited by attackers.
PaperCut said: "We are aware of confirmed customer incidents and are treating this matter with the highest priority."
The Application Server is the brain of both PaperCut NG and MF, and there is normally just one per organization.
The vendor is still investigating the incident and says it will publish specific indicators of compromise when they pinpoint them.
Interim general indicators listed by the vendor: alerts from intrusion detection, endpoint security or network monitoring involving the PaperCut Application Server, particularly suspicious post-exploitation activity from pc-app.exe; missing, unexpectedly truncated or deleted PaperCut server.log files; and the presence of either "ERROR No suitable driver found for jdbc:no:x" or "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST" in server.log.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Vendor-attested, technically unspecified
The core assertions are directly attributable to the vendor's own security bulletin, including a verbatim confirmation of customer incidents and reproducible detection artifacts (pc-app.exe activity, server.log tampering, two exact error strings). Against that, the flaw has no CVE, no affected-version list, no vulnerability class, and no patch; remote exploitability is inferred from mitigation wording rather than stated; and only one publisher covers it, with no independent telemetry.
Confirmed but unquantified incidents
Real-world uptake of the attack is established in kind but not in degree: the vendor confirms customer incidents, yet the supplied material gives no incident count, no victim identification, no estimate of internet-exposed Application Servers, and no measure of how many organizations have applied the restriction. Product footprint (offices, schools, copier fleets across most major brands) is described qualitatively only.
Close to aligned, mildly ahead of verifiable detail
The 'under active attack' framing is grounded in the vendor's own confirmation rather than speculation, and the coverage stays close to the bulletin. The small positive gap reflects that urgency language and the 2023 Clop/LockBit comparison run slightly ahead of what is verifiable today, since the vulnerability is unnamed, unscored, unpatched, and the incident count is undisclosed.
Vendor-controlled narrative, mild publisher funnel
All substantive facts originate with the affected vendor, which has an obvious interest in withholding exploitable detail and steering attention to a mitigation customers can self-apply; that shapes what is disclosed and what stays unnamed. On the publisher side, the piece closes with a breaking-news subscription call-to-action, a mild engagement incentive, but the reporting itself is restrained and attributed.
Moderate: solid attribution, thin corroboration
Confidence is supported by clean, verbatim attribution to the vendor and by actionable, specific detection artifacts, and limited by the single-publisher cluster, the absence of a CVE or patch, and the lack of any independent measurement of exposure or victim count. The direction of the story is reliable; its magnitude is not yet establishable.
product
Anthropic's usage policy says no explicit content. Opus 4.6 said yes 10 times out of 10.1 distinct publisher
security
GitLab 19.3 puts agent runtime, inference models and secrets under one permission model1 distinct publisher
security
An agent guard that runs on your laptop, and cannot tell you whether anyone keeps it on1 distinct publisher
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026