Vendor Security Bulletin Triage Lab

Goal

Distinguish three tasks that are often collapsed into “install the patch”: determine exposure, remediate the vulnerability, and investigate possible compromise.

Activity

Working from the PaperCut NG/MF security bulletin and CISA Known Exploited Vulnerabilities Catalog, review a fictional organization’s asset record and sanitized log excerpts.

  1. Identify whether the fictional server is in scope and which fixed release it needs.
  2. Sort the evidence into normal activity, suspicious indicators, and facts that still need verification.
  3. Write two response paths: one for a vulnerable system with no evidence of compromise, and one for a system showing an indicator such as unexpected child shells, missing logs, a suspicious JDBC string, or an unapproved remote-access tool.
  4. Put the actions in a defensible order: preserve evidence, isolate when warranted, notify the system owner, patch, verify, recover, and monitor.

Deliverable

Submit a one-page triage memo containing:

  • the affected asset and exposure decision;
  • the fixed release and verification method;
  • a short indicators-of-compromise table;
  • the first five actions for each response path; and
  • one sentence explaining why patching alone cannot prove that an exploited system is clean.

Discussion and safety

Use only the fictional inventory and instructor-provided log excerpts. Do not scan, probe, exploit, or alter a real PaperCut installation. Discuss why an emergency patch and an incident investigation answer different questions, and when a help-desk technician should escalate to an incident-response team.

Source material

This lab was first developed from the PTIR Daily Briefing — September 1, 2026. PaperCut’s urgent advisory describes two vulnerabilities under active exploitation, a current emergency patch, and concrete investigation indicators. It generated the lab because it lets beginning students practice converting a vendor bulletin into a safe operational decision without reproducing an exploit. Consult the original PaperCut security bulletin.

Written on September 1, 2026