PaperCut — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
December 19, 2025
Last Seen
September 2, 2026

Related Threat Clusters

  • Critical Cleo Harmony Vulnerability Exploited

    A new authentication bypass vulnerability, tracked as CVE-2026-84115, has been discovered in the Cleo Harmony file transfer application. This flaw affects the JWT refresh token logic, allowing remote attackers to…

    2 articles · Updated September 2, 2026
  • PaperCut NG/MF Vulnerability Under Active Exploitation

    On August 27, 2026, PaperCut issued an urgent advisory regarding a zero-day vulnerability affecting its NG and MF print management software. This flaw allows unauthenticated attackers to execute arbitrary Java code…

    54 articles · Updated August 27, 2026
  • Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed

    Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to…

    5 articles · Updated August 31, 2026
  • RevStealer Malware Distributed via Fake Claude Opus 5 App

    RevStealer, a new Windows infostealer, is being distributed through a malicious GitHub repository masquerading as a free version of Anthropic's Claude Opus 5. This malware targets sensitive data such as passwords,…

    7 articles · Updated August 31, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1922 articles · Updated February 12, 2026
  • Clop Ransomware Group Breaches University of Phoenix Data of 3.5 Million

    The University of Phoenix experienced a data breach affecting 3.5 million individuals, attributed to the Clop ransomware group exploiting a zero-day vulnerability in Oracle's enterprise software. The attackers accessed…

    3 articles · Updated December 30, 2025
  • Clop Ransomware Targets Gladinet CentreStack Servers for Data Theft

    The Clop ransomware group is conducting a data extortion campaign against Gladinet CentreStack file servers. This attack exploits multiple security vulnerabilities in CentreStack and its related product, Triofox,…

    6 articles · Updated December 19, 2025

Recent Intelligence Reports

  • Exploit Published for Fresh Cleo Harmony Vulnerability — Securityweek · September 2, 2026
  • Fake Claude Opus 5 app delivers malware and wipes its own tracks — Helpnetsecurity · September 1, 2026
  • Critical Ruby on Rails Vulnerability in Attackers' Crosshairs — Securityweek · August 31, 2026
  • PaperCut zero — Feeds.4Sysops · August 28, 2026
  • Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood — Theregister · August 28, 2026
  • PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE — Huntress · August 28, 2026
  • PaperCut NG/MF Vulnerability Actively Exploited in Attack — Cybersecuritynews · August 27, 2026
  • Storm-1175 Exploits Flaws in High — Infosecurity-Magazine · April 7, 2026

CVSS v3.1 Breakdown