MelbourneAttackers found PaperCut’s flaw before its advisory.
Print servers hold domain-level credentials inside hospitals and governments, almost unmonitored.
PaperCut has been a ransomware entry point before, and defenders learned of this bug from the attack, not the notice.
Unpatched on-premises deployments outside wealthy institutions face the longest exposure until they upgrade.
Sources: The Record