Skip to content
tag — papercut

grep -rl "papercut" ./articles

#papercut

3 articles

The print server held the LDAP bind credentials. That is what they came for

2026-09-07Security

Arctic Wolf has published what attackers do after exploiting the two PaperCut zero-days against schools and universities: create an account, dump the SAM hives, and grep the PaperCut config for the strings password, secret, ldap, bind and token. The print server is domain-joined and nobody's threat model has it on the list.

PaperCut is being exploited, and one of the signs is that your log file is missing

2026-08-29Security

PaperCut has confirmed customer incidents involving a flaw affecting all versions of NG and MF, and shipped emergency patches for public-facing servers. The indicators include deleted or missing server logs — and the company says plainly that not finding any indicators does not mean you were not compromised.