PaperCut Is Under Active Attack, Plus 4 Tech Stories
PaperCut has spent the weekend doing the sort of emergency security work nobody wants to be doing over a weekend. Its NG and MF print-management servers are being actively exploited, the first emergency fix needed a second round of hardening, and the company is still working toward a normal release. If you administer PaperCut, this is not one to put on Monday’s list.
And that isn’t the only trust-boundary story this morning. Newly public court filings show DHS using a customs summons to seek journalists’ records without first going to a judge, McKesson has confirmed data theft from third-party applications, Lucid Air owners have a park-outside recall, and music publishers have opened another important front in the argument over how AI companies acquired their training data.
PaperCut is under active attack, and the first emergency patch wasn’t enough
PaperCut says it has confirmed customer incidents involving active exploitation of PaperCut NG and PaperCut MF. The company now considers every version potentially affected.
The attack chain involves two vulnerabilities. CVE-2026-81578 is an authentication bypass that can let a remote, unauthenticated request trigger certain administrative backend actions before access checks finish. CVE-2026-82078 involves unsafe dynamic loading of database-driver classes. Once an attacker has manipulated the right configuration, that second flaw can be turned into execution of Java bytecode inside the PaperCut server process.
In less compressed English: the first problem can let somebody who shouldn’t be an administrator change trusted settings; the second can turn those changed settings into code execution on the server. Huntress says it saw exploitation in two customer environments and reproduced the full pre-authentication remote-code-execution chain on a stock installation.
PaperCut released an emergency patch, then released Emergency Patch Release 2 after its own team and outside researchers found that more hardening was needed. PaperCut explicitly recommends installing Release 2 even if you already installed the first emergency patch. Release 2 is available for versions 24, 25, and 26. If you’re on version 23 or older, PaperCut says to upgrade to a supported current version.
There are two things I would do before worrying about anything clever. First, if the Application Server can be reached from the public internet, restrict its web interfaces to trusted addresses now. PaperCut says to do that even if you’ve seen nothing suspicious. Second, install Release 2 on the primary Application Server and the relevant Site Servers and secondary/print servers.
The emergency patch has created some operational pain: PaperCut is investigating reports that SAML and external database Card/ID lookups don’t behave correctly afterward. For SQL Server card lookups using the old jTDS driver, it now recommends moving to Microsoft’s supported SQL JDBC driver as a first step. That is a troubleshooting problem. It is not a reason to put the vulnerable build back on an internet-facing server.
If you suspect compromise, this is no longer a normal “patch and move on” situation. PaperCut recommends preserving backups, wiping and rebuilding the Application Server, restoring a known-clean backup from before the suspicious activity, and activating your incident-response process. Its bulletin also lists log entries and suspicious pc-app.exe activity worth hunting for.
Keeping a website running is its own job. Raymond Tec provides website security and maintenance, including updates, backups, monitoring, access cleanup, recovery planning, and help when something has already gone sideways.
DHS used a customs summons to seek journalists’ records without a judge
A Guardian investigation based on newly public court filings shows the Department of Homeland Security using 19 U.S.C. § 1509 — a records-summons provision in federal customs law — to seek phone, social-media, and financial records involving journalists, nonprofits, and unions without first obtaining a warrant.
The clearest example involves journalists Georgia Fort and Don Lemon, who have pleaded not guilty to charges stemming from their coverage of a January protest at a Minnesota church. Federal prosecutors twice asked a judge for account information tied to their YouTube channels. The judge rejected the requests, finding the government had not established probable cause and saying the journalists should have an opportunity to challenge the demand.
DHS later sent Google an administrative summons under 19 U.S.C. § 1509. That statute sits in the customs code and authorizes records demands for investigations involving duties, fees, taxes, penalties, and compliance with laws administered by the old Customs Service. The government’s position, described in court filings, is that the final phrase gives DHS broader investigative authority than customs matters alone. Former DHS lawyers and civil-liberties groups quoted by the Guardian dispute that reading.
Google did not comply with the demand for the YouTube information, saying DHS had not shown how the request related to a customs investigation. T-Mobile did provide six months of Fort’s phone records — logs covering more than 10,000 calls and text messages — and Fort learned about that collection later through the criminal case. DHS and DOJ declined the Guardian’s request for comment on their use of the summons.
The technical-policy issue here is bigger than which side you take in the underlying protest case. A warrant puts a judge between the government and the requested data. An administrative summons does not do that up front. If an agency can use a specialized records power after a judge has refused a warrant for related information, the scope of that power and the ability of a user or provider to challenge it become very consequential privacy questions.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
McKesson confirms data theft; the giant “284 million” number is not confirmed
Healthcare and pharmaceutical distributor McKesson told the SEC Friday that it discovered a cybersecurity incident on August 25. In a separate customer notice, the company confirmed unauthorized access to third-party applications and the exfiltration of data. McKesson says the investigation is still early and has not yet determined that the incident is material to the company.
This is where the headline needs brakes. The ShinyHunters extortion group told BleepingComputer that it used voice phishing against employees, compromised multiple Okta accounts, reached Salesforce and Snowflake, and stole roughly a terabyte of data containing about 284 million patient-related records.
McKesson has not confirmed that attack path, the claimed volume, or the contents of the stolen data. And “284 million records” is not the same thing as “284 million patients.” A database can contain many rows about one person. Until McKesson finishes enough of its investigation to identify the affected data and people, turning the attacker’s raw record count into a victim count would be guesswork.
For patients, there is no useful mass action I can recommend beyond being more skeptical of pharmacy, insurance, and healthcare messages until notifications clarify who was affected. For businesses, the alleged intrusion method is another reminder that strong identity security has to include the help desk and phone call. An MFA system is considerably less impressive if a convincing caller can talk somebody into resetting or approving the account.
Business IT goes well beyond the website
Your business also depends on workstations, cloud accounts, browsers, Wi-Fi, remote access, collaboration tools, and all the other technology that quietly becomes infrastructure. Raymond Tec works across that whole stack, whether the problem lives on a server, on a desk, or somewhere in between.
Lucid Air owners should park outside until the fire-risk update is installed
Lucid is recalling 27,185 Air sedans from model years 2022 through 2026 because an exterior-lighting circuit can draw too much current, overheat, and create a fire risk. The same failure can knock out exterior lighting and increase crash risk.
NHTSA’s recall instructions, reported by Reuters, tell owners to park outside and away from structures until the remedy is installed. The interesting part is that the remedy is software. Lucid’s updated control logic lowers the electronic-fuse thresholds and stops a faulted circuit from being repeatedly energized during the same key cycle.
Lucid is delivering the fix over the air in software version 2.10.0 or later, and NHTSA says 20,719 of the affected cars had already received it when the recall was announced. So if you own an Air, this is a wonderfully simple check: confirm the recall status and software version. If the update is still pending, follow the park-outside instruction until it lands.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Music publishers’ new Anthropic lawsuit is really about where training copies came from
Sony Music Publishing, Warner Chappell, and other music publishers filed a new federal copyright lawsuit Friday against Anthropic and co-founders Dario Amodei and Benjamin Mann. The complaint alleges Anthropic illegally torrented, scraped, and downloaded copyrighted works — including material containing lyrics and sheet music — to build training libraries for Claude. Anthropic says it disagrees with the allegations and will defend itself.
That wording matters because “is AI training copyright infringement?” has become a dangerously compressed question. The courts have already been separating at least two issues: what an AI developer may lawfully do with a work during training, and whether the developer lawfully obtained the copy it put into the training library in the first place. This lawsuit leans heavily on the second question.
The case is Sony Music Publishing (US) LLC et al. v. Anthropic PBC et al. in the Northern District of California. At this point these are allegations, not findings. But the distinction is important for the larger AI-copyright fight. A court could decide that a particular use during model training is legally permissible without deciding that pirating the source material to create the training archive was permissible too.
There is a useful common thread through an otherwise strange Sunday mix. PaperCut trusted configuration changes that an unauthenticated visitor could reach. McKesson’s attackers allegedly got leverage through trusted identities. The government is asserting that a trusted administrative-summons power reaches farther than its critics say it does. Lucid is changing how much current software will allow a trusted circuit to draw. And Anthropic’s new lawsuit asks whether a potentially lawful use can rest on an allegedly unlawful copy.
“The system allowed it” is not the end of the analysis. Usually, that’s where the interesting question starts.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- PaperCut: urgent NG/MF security bulletin and Emergency Patch Release 2
- Huntress: PaperCut active exploitation and pre-auth RCE chain
- The Guardian: DHS use of 19 U.S.C. § 1509 summonses
- Cornell Legal Information Institute: 19 U.S.C. § 1509
- McKesson: August 28 SEC Form 8-K
- BleepingComputer: McKesson breach and ShinyHunters claims
- Reuters: Lucid Air fire-risk recall
- Federal docket: Sony Music Publishing et al. v. Anthropic
- TechCrunch: Sony and Warner lawsuit and Anthropic response
