Hackers are exploiting PaperCut flaws to steal credentials from schools and universities. Learn how the attack works and what you can do to stay protected.
### The Printer Is the New Front Door for Hackers
You know that big office printer sitting in the corner? The one everyone ignores until it jams? Turns out, it's become a favorite target for cybercriminals. And right now, they're using it to break into schools and universities across the U.S. and Europe.
Security researchers at Arctic Wolf recently spotted attackers exploiting two flaws in PaperCut, a popular print management tool. The bugs β tracked as CVE-2026-81578 and CVE-2026-82078 β chain together to let bad actors bypass login screens and run their own commands on vulnerable servers. Once inside, they poke around, steal credentials, and look for ways to dig deeper.
### What Exactly Are They After?
Credentials. Usernames. Passwords. Anything that gets them into student portals, faculty email, and internal systems. It's not about the printers themselves β it's about the keys they hold.
Here's the kicker: many schools run PaperCut on-premises, often on older Windows or Linux servers that don't get patched quickly. That makes them low-hanging fruit for attackers who know exactly what to look for.
> "The education sector is a goldmine for credential thieves because it's large, decentralized, and often under-resourced when it comes to security," one researcher noted.
And once they have those credentials, they can sell them on dark web markets, use them for phishing campaigns, or pivot into other networks.
### Why Schools Are Such Easy Targets
- **Tight budgets**: IT teams are stretched thin, and security upgrades often take a back seat.
- **Outdated software**: Many institutions still run legacy systems that haven't been patched in months.
- **Open networks**: Campus Wi-Fi and shared devices make lateral movement a breeze for attackers.
- **Valuable data**: Student records, research data, and financial info are all up for grabs.
It's a perfect storm. And the attackers know it.
### What You Can Do About It
First, if you're running PaperCut, patch it. Now. The vulnerabilities are already being exploited in the wild, and waiting even a few days could be costly. Check for updates from PaperCut's official channels and apply them immediately.
Second, segment your network. Don't let a compromised print server talk directly to your domain controller or student database. Use VLANs and firewalls to limit how far an attacker can move.
Third, monitor for unusual activity. Look for spikes in login attempts, strange command executions, or outbound traffic to unknown IPs. Tools like SIEM or even basic log analysis can catch these early.
Finally, consider antidetect browsers for your security team. Wait, what? Hear me out. These browsers let you create isolated profiles with unique fingerprints, which is incredibly useful for safely investigating malicious sites or testing phishing pages without exposing your real identity or risking your main system. It's a niche tool, but for threat intelligence and red teaming, it's a game-changer.
### The Bigger Picture
This isn't just about PaperCut. It's a reminder that every connected device β printers, cameras, HVAC systems β is a potential entry point. Attackers are opportunistic. They'll exploit whatever is easiest.
So the next time you walk past that printer, remember: it's not just spitting out paper. It could be spitting out your credentials.
Stay safe, patch fast, and keep an eye on the boring stuff. That's where the real threats hide.