CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

PaperCut NG/MF, Scan-to-Fax path traversal to OS command execution for an authenticated administrator (CVSS 4.0 7.3), fixed in 26.0.5 and 25.0.13; part of watchTowr's pre-auth chain against the 28 August emergency build

cve · CVE-2026-82077

Coverage
1
first 2026-08-29 → last 2026-10-10
Latest activity
2026-10-10
A pre-auth RCE chain in PaperCut NG/MF was exploited before any patch existed; tested maintenance releases…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education, healthcare
Sources cited
9
8 hosts

Action items (3)

Do-now tasks recorded on the entries about CVE-2026-82077, newest first. Check the date before acting on an older one.

  • Upgrade every PaperCut NG/MF Application Server, Site Server and secondary/print server to the security maintenance release for its line (26.0.5, 25.0.13 or 24.1.10), starting with any still on Emergency Patch Release 1 or 2, and note that the emergency builds do not carry the fix for CVE-2026-82077, an administrator-only Scan-to-Fax code-execution flaw that the vendor's September bulletin lists as fixed in 26.0.5 and 25.0.13 and does not list for 24.1.10; for v23 and earlier, immediately restrict the Application Server's web interface to trusted/internal IP addresses only; no patch exists for that line.
    2026-08-29CVE-2026-81578 +2
  • Before patching or restarting an internet-facing server, preserve the server/logs directory and process tree; check server.log for the two vendor-documented error strings and for an unexplained gap or truncation, check derby.log for a Derby boot line naming an in-memory database directory ending in "pwn", and hunt for a Windows service named "Remote Access Service" running SimpleService.exe (SimpleHelp) or an unexpected AnyDesk install, as PaperCut's own published incident data names both as an observed post-compromise access method.
    2026-08-29CVE-2026-81578 +2
  • Given GreyNoise's confirmed domain-admin escalation paths, verify no PaperCut Application Server is domain-joined with a privileged service account or hosted on a domain controller, and confirm domain controllers reachable from any PaperCut host are patched against the 2021 noPac flaws (CVE-2021-42278/CVE-2021-42287); GreyNoise reports the AI-orchestrated campaign reaching full domain admin through these paths in as little as five minutes after initial access.
    2026-08-29CVE-2026-81578 +2

Defender insights

What each entry about CVE-2026-82077 tells a defender to do, newest first.

2026-08-29HIGHexploitedA pre-auth RCE chain in PaperCut NG/MF was exploited before any patch existed; tested maintenance releases now replace three emergency patches

Triage

Story timeline

  1. 2026-08-29CVE-2026-82078 / CVE-2026-81578, PaperCut NG/MF: an Apache Tapestry request-routing confusion chains an unauthenticated config rewrite to arbitrary code execution, exploited before a patch existed
    deep-diveA pre-auth RCE chain in PaperCut NG/MF was exploited before any patch existed; tested maintenance releases now replace three emergency patches
ATT&CK techniques (11 across 9 tactics)

11 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts: Domain Accounts · Exploit Public-Facing Application
  • ExecutionCommand and Scripting Interpreter: JavaScript
  • PersistenceValid Accounts: Domain Accounts · Create Account: Domain Account
  • Privilege EscalationValid Accounts: Domain Accounts
  • StealthIndicator Removal: File Deletion · Valid Accounts: Domain Accounts
  • Credential AccessOS Credential Dumping: LSASS Memory · OS Credential Dumping: DCSync
  • DiscoveryProcess Discovery · System Information Discovery
  • Lateral MovementUse Alternate Authentication Material: Pass the Hash
  • Command and ControlRemote Access Tools

Initial Access TA0001

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

Execution TA0002

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

Persistence TA0003

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

T1136.002Create Account: Domain Account×1

Adversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover user, administrator, and service accounts. With a sufficient level of access, the <code>net user /add /domain</code> command can be used to create a domain account.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

Privilege Escalation TA0004

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

Stealth TA0005

T1070.004Indicator Removal: File Deletion×1

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

T1078.002Valid Accounts: Domain Accounts×1

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

Credential Access TA0006

T1003.001OS Credential Dumping: LSASS Memory×1

Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

T1003.006OS Credential Dumping: DCSync×1

Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

Discovery TA0007

T1057Process Discovery×1

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

T1082System Information Discovery×1

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

Lateral Movement TA0008

T1550.002Use Alternate Authentication Material: Pass the Hash×1

Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls. Pass the hash (PtH) is a method of authenticating as a user without having access to the user's cleartext password. This method bypasses standard authentication steps that require a cleartext password, moving directly into the portion of the authentication that uses the password hash.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

Command and Control TA0011

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-08-29/papercut-ng-mf-tapestry-request-confusion-preauth-rce · ATT&CK page ↗

Entries about PaperCut NG/MF, Scan-to-Fax path traversal to OS command execution for an authenticated administrator (CVSS 4.0 7.3), fixed in 26.0.5 and 25.0.13; part of watchTowr's pre-auth chain against the 28 August emergency build (1)

2026-08-29 · view entry permalink →

HIGHCVE-2026-81578 +2exploitedupdatedNATOB1

CVE-2026-82078 / CVE-2026-81578, PaperCut NG/MF: an Apache Tapestry request-routing confusion chains an unauthenticated config rewrite to arbitrary code execution, exploited before a patch existed

PaperCut has been targeted before: Rapid7 notes that in 2023 CVE-2023-27350 was broadly exploited in the wild by multiple threat-actor groups, including ransomware operators, which raises the urgency of this new zero-day (Rapid7, 2026-08-28). PaperCut disclosed on 27 August 2026 that it was investigating active exploitation of a new flaw in the same product line, before any CVE, patch or public technical detail existed (watchTowr, 2026-10-09); Rapid7 relays PaperCut's statement that information supplied by a university customer's security team and its digital forensics and incident response team enabled PaperCut to reproduce the vulnerability (Rapid7, 2026-08-28).

PaperCut's Application Server runs on the Apache Tapestry web framework, whose "complex direct" request format lets a single HTTP request name one page to render and a different page's component to actually execute. PaperCut's own authorization check validates only the page selected for rendering, not the component that runs behind it, so a request that asks Tapestry to render the public, unauthenticated Error, Exception, or Home page while invoking the administrative ConfigEditor or UserList component bypasses authentication entirely (Rapid7, 2026-08-28). Through three such POST requests, /app?service=direct/1/Error/ConfigEditor/quickFindForm, .../ConfigEditor/$Form, and .../UserList/$QuickFind.$Form, an unauthenticated attacker rewrites four external card/ID lookup settings (user-lookup.db-driver, user-lookup.db-url, user-lookup.id-to-username-sql, user-lookup.enabled) that normally point PaperCut at an administrator-configured external card database (Rapid7, 2026-08-28). Redirected instead to an attacker-controlled JDBC target through PaperCut's bundled Apache Derby driver and its foreignViews feature, the connection reaches an attacker-controlled H2 database whose inline INIT statement creates a JavaScript-backed trigger; PaperCut's bundled Nashorn JavaScript engine then executes that trigger to launch an operating-system process, full remote code execution as the PaperCut server, triggered the moment the forged UserList search runs the malicious lookup (Rapid7, 2026-08-28). This is a two-CVE chain: CVE-2026-81578 (CWE-306, missing authentication) is the pre-auth entry that gains write access to the server configuration; CVE-2026-82078 (CWE-470, unsafe dynamic class loading) is the flaw that turns a reconfigured database connection into arbitrary Java bytecode execution once that write access is held (PaperCut Software, 2026-09-10).

PaperCut treats all versions of NG and MF as potentially affected. Huntress observed two live customer exploitations: one on 26 August lasting under two minutes against version 25.0.10.75465, and a second on 27 August against version 24.1.5.71847, before Emergency Patch Release 2 extended coverage to the v24 line (Huntress, 2026-08-28). In both cases the attacker ran base64-encoded discovery commands (whoami & ver, and separately whoami & ver & tasklist) via a dropped, OS-agnostic Java .class file; in the first incident it wrote its output to a temporary file and then deleted both that file and the server's own server.log (Huntress, 2026-08-28). Huntress's own proof-of-concept reproduced the full chain against a stock PaperCut NG install and observed the code execution surface as an observable charmap.exe process running as SYSTEM, spawned under the PaperCut Application Server's own pc-app.exe process (Huntress, 2026-08-28). PaperCut released an initial emergency patch for v25 and v26 on 28 August and patches for v24 later the same day, and Rapid7 says the first patch could be bypassed by using the Home page for display while the newest version of the vendor patch remediates that bypass (Rapid7, 2026-08-28). PaperCut then superseded the earlier emergency patches with Emergency Patch Release 3 on 1 September 2026 and replaced all three emergency patches on 10 September with fully tested maintenance releases (see the updates below) (PaperCut Software, 2026-09-10). There is no fix for v23 and earlier; PaperCut's guidance for that line is to upgrade to a supported version (PaperCut Software, 2026-09-10), and Huntress estimates 47% of the roughly 2,500 PaperCut installations it tracks still run v23 or older (Huntress, 2026-08-28).

Detection, telemetry class first: alert on any child process spawned from pc-app.exe or the PaperCut Application Server's Java process, the lineage under which the observed exploitation ran its discovery commands. Web-access logs for the PaperCut Application Server should be checked for POST requests to /app?service=direct/*/{Error,Exception,Home}/ConfigEditor/* or .../UserList/$QuickFind.$Form from unauthenticated or external sources; this URL shape is not a pattern ordinary PaperCut administration produces. Two log artifacts are near-unique indicators: a server.log line reading DB URL: jdbc:derby:memory:pwn, and a corresponding derby.log entry recording Derby booting an in-memory database directory whose name ends in the literal string pwn (Huntress, 2026-08-28). PaperCut stresses that the absence of its file artifacts does not rule out compromise because the attacker may clean them up (PaperCut Software, 2026-09-10), and Huntress observed the payload deleting the server's own server.log (Huntress, 2026-08-28). The later authentication bypass that watchTowr documents reaches the Setup Wizard pages through the Home page, so requests whose service parameter routes through Home to a setup page such as SetupAdmin on a server whose setup is long complete are the matching pattern (watchTowr, 2026-10-09). Triage: an unexpectedly truncated, gapped, or missing server.log on a PaperCut Application Server is worth investigating even where no other artifact survives, since Huntress saw the payload delete that log.

PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.

PaperCut Software

PaperCut's authorization check could trust the rendered page and miss the permissions required by the component behind it.

Huntress 2026-08-28

By selecting either the public Error page or Exception page for display, an attacker can bypass authentication while invoking administrative components belonging to ConfigEditor or UserList.

Rapid7 2026-08-28

47% of the approximately 2,500 PaperCut installations Huntress tracks are running v23 or older, for which no patch is currently available.

Huntress 2026-08-28

PaperCut has been targeted in the past; in 2023, CVE-2023-27350 was broadly exploited in the wild by multiple threat-actor groups, including ransomware operators.

Rapid7 2026-08-28

Emergency Patch (Release 3) has been released by our emergency response team and supersedes Release 2. You do not need to install previous patches, this patch is an accumulation of all emergency releases. This release addresses two known regressions and adds additional hardening and mitigation against potential attack chains.

Servers that remain publicly reachable and unpatched continue to be targeted, and post-compromise behaviour observed in the second wave has been more sophisticated than in the first days of this incident.

These releases replace the emergency patches. If you are running an emergency patch build, move to a maintenance release. If you have not yet patched, upgrade now.

PaperCut Software

compromise at least 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries

GreyNoise observed the adversary achieved domain admin against only 12 victim organizations.

GreyNoise 2026-09-09

Patch contains a fix for: WT-2026-0143 (Authentication Bypass)

Patch contains a fix for: WT-2026-0144/CVE-2026-82077 (Post-Auth RCE)

Tying it all together (WT-2026-0143 + WT-2026-0144/CVE-2026-82077), we can finally pop a shell against PaperCut NG 26.0.4-PO build 76508.

watchTowr Labs 2026-10-09

If you have already upgraded to the latest release (26.0.5, 25.0.13) the issues are already addressed.

PaperCut Software
Updaterun 2026-09-03T0410Z-intelcvesactionsimmediate_actionsummarytechniquesevidencesourcing_notebody

PaperCut's Emergency Patch Release 3, published 1 September 2026, supersedes Release 2 and is cumulative, customers do not need to install the earlier releases first (PaperCut Software, 2026-09-02). Release 3 fixes two regressions Release 2 had itself introduced, broken SAML login flows, and lost support for legacy Microsoft SQL Server drivers used for external card lookup, and adds further, undisclosed hardening against the exploitation chain (PaperCut Software, 2026-09-02). PaperCut also confirms a second wave of attacks against servers that remain unpatched and internet-facing, whose post-compromise behaviour "has been more sophisticated than in the first days of this incident" (PaperCut Software, 2026-09-02). The vendor's own incident data, published 30 August as additional indicators of compromise, names a concrete follow-on chain from the original intrusion: after initial discovery commands, a PowerShell-delivered download installs a Windows service literally named "Remote Access Service" running SimpleService.exe, a SimpleHelp remote-access agent, as LocalSystem with auto-start, followed by a further download of AnyDesk; the bulletin does not state whether this specific chain recurred in the second wave or belongs only to the earlier intrusions it was published alongside (PaperCut Software, 2026-09-02). Mobility Print and Print Deploy server components are unaffected; Site Servers and secondary/print servers do need the same update as the primary Application Server (PaperCut Software, 2026-09-02).

Updaterun 2026-09-10T0410Z-intelsummarytechniquesactionssourcesevidencebody

GreyNoise's Global Observation Grid documents an AI-agent-orchestrated exploitation campaign against this chain beginning 31 August 2026, run by a likely Russian-speaking operator already tracked since July 2026 for attacks on Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox VE targets (GreyNoise, 2026-09-09). The operator built and tested both CVEs' exploits in a self-hosted PaperCut/Active Directory lab, sourced target lists via the Netlas.io scanning service, then deployed hundreds of AI agents, built on OpenAI's Codex harness paired with a DeepSeek model, to opportunistically "compromise at least 440 instances of PaperCut MF/NG hosted by 395 identified victim organizations in 48 countries" (GreyNoise, 2026-09-09). GreyNoise reports the adversary "went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds" (GreyNoise, 2026-09-09), with one US high school reaching full domain admin in seven minutes from initial access. Domain admin was ultimately reached against only twelve of the 395 compromised organizations, "GreyNoise observed the adversary achieved domain admin against only 12 victim organizations" (GreyNoise, 2026-09-09), via three paths: LSASS credential harvesting for pass-the-hash against the domain controller when the PaperCut host was domain-joined; the 2021 noPac flaws (CVE-2021-42278/CVE-2021-42287) where those remained unpatched; or directly adding a new account to Domain Admins when the PaperCut host itself ran on the domain controller or under a domain-admin service account. All three paths finished with a DCSync-based full NTDS.DIT credential dump; Cloudflare's WAF defeated the adversary against at least one targeted instance. This delta is reported by GreyNoise alone; a second independent source had not corroborated it as of this update.

Updaterun 2026-09-29T2134Z-auditsummaryimmediate_actioncvesactionsevidenceheadlinetagssourcesbody

PaperCut published security maintenance releases 26.0.5, 25.0.13 and 24.1.10 for NG and MF on 10 September 2026. Unlike the emergency patches, they went through the vendor's full release testing, carry new version numbers and release notes, and address all the CVEs in the advisory with the same protection as the emergency patches plus additional hardening. PaperCut's instruction is plain: "These releases replace the emergency patches. If you are running an emergency patch build, move to a maintenance release. If you have not yet patched, upgrade now." A server already on Emergency Patch Release 3 is protected against both CVEs and can schedule the upgrade through normal change control, while one still on Release 1 or 2 should move now. Site Servers and secondary/print servers should be updated to a patched version, not just the primary Application Server (PaperCut Software, 2026-09-10).

Nothing changes for v23 and earlier: there is no emergency patch or maintenance release for that line, and the only route to a fixed build is an upgrade to a supported line (24, 25 or 26), with web access to the Application Server restricted to trusted addresses until then. PaperCut also reports that new compromises have slowed considerably and that most customers now have the Application Server behind a firewall or on a patched build, but that publicly reachable, unpatched servers are still being targeted (PaperCut Software, 2026-09-10). For an estate that patched in the first week, the task is to move each server from its emergency build to the maintenance release and confirm the version on every Site Server and secondary server, not only on the primary. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on 2026-08-31 (CISA KEV).

Updaterun 2026-10-10T0255Z-intelprioritysummaryimmediate_actiontagscvesactionssourcesevidencesourcing_notebody

watchTowr Labs published a write-up on 2026-10-09 that follows the emergency patches build by build (watchTowr, 2026-10-09). Its timeline: the patch released on 28 August (26.0.4-PO build 76508) fixed two bypasses watchTowr had reported; watchTowr then bypassed the fix for the authentication bypass again (tracked internally as WT-2026-0143, no CVE assigned) and found a new post-authentication code-execution flaw in Scan-to-Fax (WT-2026-0144, now CVE-2026-82077), which together gave a full unauthenticated chain against build 76508; the patch released on 1 September (build 76530) fixes WT-2026-0143, and 26.0.5, released on 10 September, fixes CVE-2026-82077 (watchTowr, 2026-10-09). The authentication bypass abuses the Setup Wizard forms, which the earlier patches had ignored: every stage can be reached through the Home page even after setup is complete, and watchTowr shows it modifies the administrator password (watchTowr, 2026-10-09). watchTowr also publishes a Detection Artefact Generator that tests a server's exposure to the authentication bypasses but does not run the full chain (watchTowr, 2026-10-09).

PaperCut's September security bulletin lists CVE-2026-82077 as a code-execution flaw in the Scan-to-Fax component that needs an authenticated administrator, rated CVSS 4.0 7.3, fixed in 26.0.5 and 25.0.13, and says servers already on the latest release are covered (PaperCut Software, 2026-09-24); it names no 24.x release and no emergency build. The unauthenticated chain watchTowr describes is closed by the 1 September patch, but an administrator-level foothold still reaches code execution through Scan-to-Fax until the maintenance release is installed. No source names exploitation of CVE-2026-82077 or of the Setup Wizard bypass. PaperCut says Emergency Patch Release 3 closes off additional attack vectors it has observed being exploited in the wild, without naming them (PaperCut Software, 2026-09-10).

vulnerability29 Aug 04:09Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Deep dive1

Source distribution

  • papercut.com2 (22%)
  • advisories.ncsc.nl1 (11%)
  • cert.ssi.gouv.fr1 (11%)
  • cisa.gov1 (11%)
  • greynoise.io1 (11%)
  • huntress.com1 (11%)
  • labs.watchtowr.com1 (11%)
  • rapid7.com1 (11%)