WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Joint Cybersecurity Advisory – Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Joint Cybersecurity Advisory – Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG

Author: Alec Davison

Created: Tuesday, May 16, 2023 - 15:15

Categories: Cybersecurity

WaterISAC regularly provides awareness of recent CISA reporting. While direct relevance to your utility/organization on the details of each report may vary, activity alerts like this are practical for general awareness of active threats and adversary capabilities.

CISA and the FBI recently published a joint Cybersecurity Advisory (CSA) providing network defenders recommended actions and mitigations to protect against cyber actors exploiting a vulnerability (CVE-2023-27350) in certain versions of PaperCut, a print management software. When exploited, an unauthenticated actor is able to execute malicious code remotely without credentials.

The advisory provides technical details on Bl00dy Ransomware Gang observed by the FBI in early May 2023 attempting to exploit vulnerable PaperCut servers against education facilities subsector. Some of these operations by Bl00dy Ransomware Gang led to data exfiltration, encryption and ransom notes left on victim devices. PaperCut released a patch for CVE-2023-27350 in March 2023. Users and administrators are strongly urged to immediately apply patches, and workarounds if unable to patch.

The CSA also includes indicators of compromise to help network defenders detect if this exploitation activity is on their networks. CISA and the FBI encourage network defenders to review the CSA and apply the included mitigations. See StopRansomware.gov for additional guidance on ransomware protection, detection, and response. 

To report suspicious or criminal activity related to information found in advisory, contact your local FBI field office, or the FBI’s 24/7 Cyber Watch (CyWatch) at (855) 292-3937, or by e-mail at Cy*****@*bi.gov. If you have any further questions, or to request incident response resources or technical assistance related to these threats, contact CISA at CI*************@******hs.gov. Access the full advisory at CISA.

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar