Vendor Security Bulletin Triage Lab
Goal
Distinguish three tasks that are often collapsed into “install the patch”: determine exposure, remediate the vulnerability, and investigate possible compromise.
Activity
Working from the PaperCut NG/MF security bulletin and CISA Known Exploited Vulnerabilities Catalog, review a fictional organization’s asset record and sanitized log excerpts.
- Identify whether the fictional server is in scope and which fixed release it needs.
- Sort the evidence into normal activity, suspicious indicators, and facts that still need verification.
- Write two response paths: one for a vulnerable system with no evidence of compromise, and one for a system showing an indicator such as unexpected child shells, missing logs, a suspicious JDBC string, or an unapproved remote-access tool.
- Put the actions in a defensible order: preserve evidence, isolate when warranted, notify the system owner, patch, verify, recover, and monitor.
Deliverable
Submit a one-page triage memo containing:
- the affected asset and exposure decision;
- the fixed release and verification method;
- a short indicators-of-compromise table;
- the first five actions for each response path; and
- one sentence explaining why patching alone cannot prove that an exploited system is clean.
Discussion and safety
Use only the fictional inventory and instructor-provided log excerpts. Do not scan, probe, exploit, or alter a real PaperCut installation. Discuss why an emergency patch and an incident investigation answer different questions, and when a help-desk technician should escalate to an incident-response team.
Source material
This lab was first developed from the PTIR Daily Briefing — September 1, 2026. PaperCut’s urgent advisory describes two vulnerabilities under active exploitation, a current emergency patch, and concrete investigation indicators. It generated the lab because it lets beginning students practice converting a vendor bulletin into a safe operational decision without reproducing an exploit. Consult the original PaperCut security bulletin.