PaperCut Software A.I CyberSecurity Scoring
PaperCut Software
Company Information
Website:http://www.papercut.com
Employees number:268
Number of followers:23,611
NAICS:5112
Industry Type:Software Development
Homepage:papercut.com
PaperCut Software Risk Score (AI oriented)
Between 700 and 749
PaperCut SoftwareSoftware Development
Updated:
08/04/2026
08/04/2026
747/1000
Moderate
Ba
PaperCut Software Global Score (TPRM)
xxxx
PaperCut SoftwareSoftware Development
Score locked

PaperCut SoftwareModerate
Current Score
747Ba (MODERATE)
01000
3 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
749
JULY 2026
748
JUNE 2026
748
MAY 2026
748
APRIL 2026
752
Vulnerability
06 Apr 2026 • PaperCut Software
PaperCut, Microsoft, VMware and Ivanti: Microsoft links Medusa ransomware affiliate to zero-day attacks
Storm-1175: China-Based Cybercrime Group Exploits Zero-Days in High-Speed Ransomware Attacks
747
CRITICAL-5
VMWMICPAPIVA1775500095
Storm-1175: China-Based Cybercrime Group Exploits Zero-Days in High-Speed Ransomware Attacks
Microsoft has identified Storm-1175, a financially motivated cybercriminal group based in China, as the force behind a series of high-velocity ransomware attacks leveraging zero-day and n-day exploits. The group, known for deploying Medusa ransomware, rapidly weaponizes newly disclosed vulnerabilities sometimes within 24 hours of discovery and, in some cases, a week before patches are released.
Storm-1175’s attacks follow a streamlined playbook: initial access via unpatched flaws, followed by credential theft, security tool disablement, and ransomware deployment often within days. The group has targeted organizations in healthcare, education, professional services, and finance, with significant impacts in the U.S., U.K., and Australia.
Recent campaigns have exploited over 16 vulnerabilities across 10 software products, including:
- Microsoft Exchange (CVE-2023-21529)
- PaperCut (CVE-2023-27351, CVE-2023-27350)
- Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887)
- ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708)
- JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199)
- SmarterMail (CVE-2026-23760, CVE-2025-52691)
- GoAnywhere MFT (CVE-2025-10035)
In October 2024, Microsoft reported Storm-1175 exploiting CVE-2025-10035 (GoAnywhere MFT) before a patch was available. The group has also chained exploits to create persistence, deploy remote monitoring tools, and exfiltrate data before encrypting systems.
A March 2025 advisory from CISA, the FBI, and MS-ISAC warned that Medusa ransomware attacks had compromised over 300 U.S. critical infrastructure organizations. Microsoft previously linked Storm-1175 to Black Basta and Akira ransomware campaigns exploiting a VMware ESXi flaw in July 2024.
The group’s rapid exploitation of zero-days suggests either advanced in-house capabilities or access to exploit brokers, though many attacks still rely on known (n-day) vulnerabilities. Their tactics highlight the growing threat of high-speed, financially driven cybercrime operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2026
752
FEBRUARY 2026
752
JANUARY 2026
752
DECEMBER 2025
752
NOVEMBER 2025
752
OCTOBER 2025
751
SEPTEMBER 2025
751
JANUARY 2025
754
Vulnerability
01 Jan 2025 • PaperCut Software
Ivanti, PaperCut, ConnectWise and Microsoft: Microsoft flags China-based hackers using vicious new 'rapid attack' zero-days to launch ransomware at targets across the world
Storm-1175: Rapid Ransomware Deployment via Zero-Day and N-Day Exploits
749
CRITICAL-5
CONMICPAPIVA1775607925
Storm-1175: Rapid Ransomware Deployment via Zero-Day and N-Day Exploits
A Chinese-speaking cybercriminal group, Storm-1175, is accelerating its attacks, moving from initial access to full system compromise including Medusa ransomware deployment in as little as 24 hours, according to a new Microsoft report. Unlike state-sponsored actors, the group operates for financial gain, targeting healthcare, finance, education, and professional services sectors, primarily in the U.S., U.K., and Australia.
Storm-1175 exploits a mix of zero-day and n-day vulnerabilities, often chaining flaws for maximum impact. The group has been observed abusing zero-days before public disclosure and rapidly weaponizing n-days leaving defenders minimal time to patch. Over 16 vulnerabilities across 10 products have been leveraged, including critical flaws in:
- Microsoft Exchange (CVE-2023-21529)
- PaperCut (CVE-2023-27351, CVE-2023-27350)
- Ivanti Connect Secure/Policy Secure (CVE-2023-46805, CVE-2024-21887)
- ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708)
- JetBrains TeamCity, SimpleHelp, CrushFTP, SmarterMail, and BeyondTrust
After gaining access, the group disables antivirus and endpoint protection, deploys tools for lateral movement and persistence, and exfiltrates data before encrypting systems with Medusa ransomware. Their high operational tempo and ability to identify exposed assets have made their attacks particularly effective.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JUNE 2023
754
Vulnerability
16 Jun 2023 • PaperCut Software
PaperCut
Critical Vulnerability in PaperCut NG/MF Print Management Software
751
MEDIUM-3
PAP242072925
CISA has issued an urgent warning regarding a critical vulnerability in PaperCut NG/MF print management software that threat actors are actively exploiting in ransomware campaigns. The vulnerability, tracked as CVE-2023-2533, represents a significant security risk to organizations worldwide using the affected software versions. This security flaw, categorized under CWE-352, allows attackers to potentially alter security settings and execute arbitrary code on vulnerable systems under specific conditions. The vulnerability’s severity stems from its ability to enable remote code execution (RCE), making it an attractive target for cybercriminals seeking to establish persistent access to enterprise networks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for PaperCut Software ??
What was PaperCut Software's A.I Rankiteo Cyber Score in July 2026 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in June 2026 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in May 2026 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in April 2026 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in March 2026 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in February 2026 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in January 2026 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in December 2025 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in November 2025 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in October 2025 ??
What was PaperCut Software's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on PaperCut Software's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with PaperCut Software ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view PaperCut Software's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?