No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

CISA, FBI: Ransomware Gang Exploited PaperCut Flaw Against Education Facilities

May 14, 2023
in Protection
0
Spain Arrests Hackers in Crackdown on Major Criminal Organization


The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have raised the alarm on a recent PaperCut vulnerability being exploited in ransomware attacks targeting the education sector.

Described as an improper access control issue in the PaperCut MF/NG print management system and tracked as CVE-2023-27350 (CVSS score of 9.8), the flaw allows remote, unauthenticated attackers to bypass authentication and execute arbitrary code on vulnerable devices, with System privileges.

The vulnerability was identified in PaperCut MF and NG versions 8.0 and later and was addressed in March 2023 with the release of PaperCut MF and PaperCut NG versions 20.1.7, 21.2.11, and 22.0.9.

Unpatched PaperCut servers have been targeted in malicious attacks since mid-April, with the Cl0p ransomware operator and Iranian state-sponsored threat actors seen exploiting the flaw.

Now, CISA and the FBI say that the Bl00dy ransomware gang was observed in early May 2023 attempting to exploit CVE-2023-27350 in attacks targeting the education facilities subsector.

According to the US government agencies, roughly 68% of the internet-exposed PaperCut servers in the US are maintained by the education facilities subsector. However, not all these servers are necessarily vulnerable.

The Bl00dy ransomware group, the two agencies say, has exploited unpatched PaperCut servers to gain access to victims’ networks, exfiltrate data, and encrypt systems.

Advertisement. Scroll to continue reading.

As part of the attacks, the threat actor exploited the PaperCut installations to deploy and execute legitimate remote management and maintenance (RMM) software and used the Tor network and other proxies to hide malicious network traffic.

Furthermore, CISA and the FBI also discovered that the ransomware gang downloaded and executed malware such as DiceLoader, TrueBot, and Cobalt Strike beacons.

CISA and the FBI have published indicators of compromise (IoCs), network signatures, and other rule-based detections to help organizations determine whether they have been compromised, but warn that these detections might not be enough, as attackers are known to adapt existing exploits to circumvent detections.

Monitoring system processes and reviewing the PaperCut server options to identify unknown print scripts should also help detect malicious activity related to this vulnerability.

“FBI and CISA strongly encourage users and administrators to immediately apply patches, and workarounds if unable to patch. FBI and CISA especially encourage organizations who did not patch immediately to assume compromise and hunt for malicious activity,” the agencies note.

Related: Huntress: Most PaperCut Installations Not Patched Against Already-Exploited Security Flaw

Related: Dragos Says Ransomware Gang Accessed Limited Data but Failed at Extortion Scheme

Related: Ransomware Group Claims Attack on Constellation Software

Editorial Team

Editorial Team

Related Posts

What Happens Now That Meta and YouTube Were Found Legally Negligent
Protection

What Happens Now That Meta and YouTube Were Found Legally Negligent

March 26, 2026
If I Had a Home Gym, This Is the Storage Rack I'd Buy During Amazon's Spring Sale
Protection

If I Had a Home Gym, This Is the Storage Rack I’d Buy During Amazon’s Spring Sale

March 26, 2026
This Budget Fitbit Is Only $70 During Amazon's Big Spring Sale
Protection

This Budget Fitbit Is Only $70 During Amazon’s Big Spring Sale

March 26, 2026
This Surprisingly Powerful Compressed Air Duster Is 27% Off Today
Protection

This Surprisingly Powerful Compressed Air Duster Is 27% Off Today

March 26, 2026
Google's Pixel Buds Pro 2 Are $60 Off for the Amazon Big Spring Sale
Protection

Google’s Pixel Buds Pro 2 Are $60 Off for the Amazon Big Spring Sale

March 25, 2026
Roblox Gift Cards Are Majorly Discounted During Amazon's Big Spring Sale
Protection

Roblox Gift Cards Are Majorly Discounted During Amazon’s Big Spring Sale

March 25, 2026
Load More
Next Post
Greece’s ‘greatest turnround’: from junk to investment grade

Greece’s ‘greatest turnround’: from junk to investment grade

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • L&G enters $1bn strategic partnership with Enosis Capital

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • US gasoline prices to rise after attack on Iran, analysts warn

    0 shares
    Share 0 Tweet 0

Latest News

Woman pleads not guilty to attempted murder of singer Rihanna

Woman pleads not guilty to attempted murder of singer Rihanna

March 26, 2026
0

Woman pleads not guilty to attempted murder of singer Rihanna

Stablecoins and the battle for monetary influence

What infrastructure do companies use to add stablecoin payments?

March 26, 2026
0

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes...

What Happens Now That Meta and YouTube Were Found Legally Negligent

What Happens Now That Meta and YouTube Were Found Legally Negligent

March 26, 2026
0

Mark Zuckerberg leaving Los Angeles Superior Court last month. Credit: Jon Putman/Anadolu via Getty Images On Wednesday, a Los Angeles...

Bryan Johnson: Psychedelics may revolutionize anti-aging, psilocybin enhances neuroplasticity for mental health, and the default mode network’s role in cognitive rejuvenation

Bryan Johnson: Psychedelics may revolutionize anti-aging, psilocybin enhances neuroplasticity for mental health, and the default mode network’s role in cognitive rejuvenation

March 26, 2026
0

Key Takeaways Psychedelics are being explored as potential rejuvenation protocols for anti-aging. Research on psilocybin indicates it may have significant...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.