A second PaperCut emergency patch has been released after researchers bypassed an earlier fix for two actively exploited flaws. The vulnerabilities affect PaperCut MF and PaperCut NG print management servers, particularly systems exposed to the internet.
The development leads a cybersecurity roundup published on 4 September 2026, alongside reports of Claude session hijacking, an incident at Boston Scientific and an attempted attack affecting X users. Each case involves attackers targeting trusted sessions, exposed software or account infrastructure.
PaperCut emergency patch follows bypassed fix
PaperCut issued the second emergency update after researchers found that its initial security fix could be bypassed. The underlying vulnerabilities affect the company’s MF and NG products, which organisations use to manage printing, users, quotas and access across workplace environments.
Both vulnerabilities were reported as being actively exploited. More importantly, attackers may be able to chain them to achieve pre-authentication remote code execution. This means an attacker could potentially run code on a vulnerable server without first supplying valid login credentials.
How the PaperCut attack chain works
Chaining vulnerabilities means combining two separate weaknesses so that their effects become more serious. In this case, the reported chain could take an attacker from unauthenticated access to remote code execution on an exposed PaperCut server.
Remote code execution can give an attacker a foothold on the affected host. The precise outcome will depend on the server’s configuration, privileges and network position, but successful exploitation could permit malicious commands or software to run within the environment.
The first fix was therefore not the end of the issue. Once researchers identified a route around that protection, PaperCut released a second emergency patch to close the bypass. Organisations that installed only the initial update may consequently remain exposed and should not assume that the earlier remediation is sufficient.
The reported affected products are PaperCut MF and PaperCut NG. The roundup does not provide affected version numbers or identify the precise patched releases, so administrators should confirm the required build directly against PaperCut’s current security guidance before treating a server as protected.
Internet-facing print servers face the clearest risk
The PaperCut emergency patch is particularly relevant to organisations running MF or NG servers that can be reached from the public internet. External exposure gives attackers an opportunity to probe vulnerable systems directly, without first gaining access to the internal network.
Small and medium-sized businesses may be among those at risk because print management servers can be deployed with limited security oversight. However, exposure rather than organisation size is the decisive factor. Any accessible and unpatched PaperCut server could present a target while exploitation remains active.
The sequence of an original fix, a discovered bypass and a second emergency release also changes the immediate response priority. Security teams need to verify the actual installed version, rather than relying on a record showing that an earlier patching task was completed.
Claude sessions targeted by infostealer malware
The same roundup reports that Anthropic has warned about infostealers stealing active Claude sessions. Malware families named in the report include Vidar, LummaC2, RedLine and Atomic Stealer.
These tools are commonly distributed through pirated software and other illicit downloads. Once running on a device, an infostealer searches for valuable information such as browser data, credentials and session material. In the Claude campaign, stolen active sessions could let an attacker enter an account without going through the normal sign-in process.
Why session theft can bypass account controls
After a user signs in, a service normally places session data on the device so that the user does not have to re-enter a password on every page. If malware steals that valid session material, the service may initially treat the attacker as the already authenticated user.
This can allow session hijacking to bypass both the password and two-factor authentication. Those controls may have worked correctly during the original login, but the attacker is reusing evidence that authentication has already taken place rather than attempting a fresh login.
Anthropic warned that criminals could access Claude through the victim’s session and consume paid AI usage. Depending on what remains available inside the account, unauthorised access could also expose conversations or other information associated with the active session, although the roundup does not report a confirmed data breach or identify the number of affected users.
Boston Scientific investigates on-premises incident
Boston Scientific also disclosed an ongoing cybersecurity incident affecting certain on-premises systems. The company said it had identified no impact on its cloud-based applications.
As of the roundup’s publication on 4 September 2026, Boston Scientific had reported no confirmed data breach. It also said there had been no evidence of unauthorised activity since 25 August 2026, while its investigation continued.
Those statements define the known scope at that stage rather than proving that every possible effect had been ruled out. The incident remained under investigation, but the distinction between affected on-premises systems and unaffected cloud applications provided an important boundary for the company’s response.
US authorities investigate attack targeting X users
The roundup also says the US Department of Justice is investigating an attempted large-scale cyberattack targeting hundreds of thousands of X users. The available report links the activity to the platform’s password-related infrastructure, but does not provide enough detail to establish the complete attack method or whether accounts were successfully compromised.
The scale is significant because password and account recovery systems sit between users and their online identities. Attempts to manipulate those systems can create large volumes of fraudulent requests, disrupt access or support account takeover activity. However, the report describes this as an attempted attack, so the number targeted should not be treated as the number successfully breached.
Responding to the PaperCut emergency patch
For organisations using PaperCut, the immediate task is to identify every MF and NG server and establish whether it is publicly reachable. Teams should then verify that the second emergency update, not merely the bypassed first fix, has been installed.
- Inventory PaperCut MF and NG deployments, including overlooked or externally hosted servers.
- Confirm installed builds against PaperCut’s latest security advisory and second patch.
- Restrict unnecessary internet access to print management interfaces.
- Review server, authentication and network logs for activity that may indicate exploitation.
- Investigate unexpected processes, commands or configuration changes on exposed hosts.
For Claude users, affected devices should be treated as the source of the risk. Removing infostealer malware, ending active sessions and avoiding pirated downloads are directly relevant steps. Simply changing a password may not invalidate session material that has already been stolen, so session revocation should form part of the response.
Originally reported by thecyberexpress.com.





