Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation

CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation

Posted on July 29, 2025July 29, 2025 By CWS

Jul 29, 2025Ravie LakshmananVulnerability / Software program Safety
The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Monday added a high-severity safety vulnerability impacting PaperCutNG/MF print administration software program to its Recognized Exploited Vulnerabilities (KEV) catalog, citing proof of energetic exploitation within the wild.
The vulnerability, tracked as CVE-2023-2533 (CVSS rating: 8.4), is a cross-site request forgery (CSRF) bug that might lead to distant code execution.
“PaperCut NG/MF accommodates a cross-site request forgery (CSRF) vulnerability, which, below particular situations, might probably allow an attacker to change safety settings or execute arbitrary code,” CISA mentioned in an alert.PaperCut NG/MF is often utilized by faculties, companies, and authorities places of work to handle print jobs and management community printers. As a result of the admin console sometimes runs on inner internet servers, an exploited vulnerability right here might give attackers a straightforward foothold into broader methods if missed.

In a possible assault state of affairs, a menace actor might leverage the flaw to focus on an admin person with a present login session, and deceive them into clicking on a specifically crafted hyperlink that results in unauthorized modifications.
It is at the moment not recognized how the vulnerability is being exploited in real-world assaults. However provided that shortcomings within the software program resolution have been abused by Iranian nation-state actors in addition to e-crime teams like Bl00dy, Cl0p, and LockBit ransomware for preliminary entry, it is important that customers apply mandatory updates, if not already.On the time of writing, no public proof-of-concept is out there, however attackers might exploit the bug by a phishing e-mail or a malicious website that methods a logged-in admin into triggering the request. Mitigation requires greater than patching—organizations must also assessment session timeouts, limit admin entry to recognized IPs, and implement robust CSRF token validation.
Pursuant to Binding Operational Directive (BOD) 22-01, Federal Civilian Govt Department (FCEB) companies are required to replace their cases to a patched model by August 18, 2025.
Admins ought to cross-check with MITRE ATT&CK methods like T1190 (Exploit Public-Going through Software) and T1071 (Software Layer Protocol) to align detection guidelines. For broader context, monitoring PaperCut incidents in relation to ransomware entry factors or preliminary entry vectors may help form long-term hardening methods.

The Hacker News Tags:Active, Adds, Catalog, CISA, CSRF, Exploitation, KEV, NGMF, PaperCut, Vulnerability

Post navigation

Previous Post: Creating Realistic Deepfakes Is Getting Easier Than Ever. Fighting Back May Take Even More AI
Next Post: GitHub Outage Disrupts Core Services Globally for Users

Related Posts

Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More Oracle 0-Day, BitLocker Bypass, VMScape, WhatsApp Worm & More The Hacker News
FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE The Hacker News
UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud UNC2891 Breaches ATM Network via 4G Raspberry Pi, Tries CAKETAP Rootkit for Fraud The Hacker News
NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft NGate Malware Exploits HandyPay App in Brazil for NFC Data Theft The Hacker News
TikTok Slammed With €530 Million GDPR Fine for Sending E.U. Data to China TikTok Slammed With €530 Million GDPR Fine for Sending E.U. Data to China The Hacker News
China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft
  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft
  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark