Attackers found PaperCut’s flaw before its advisory.

Print servers hold domain-level credentials inside hospitals and governments, almost unmonitored.

PaperCut has been a ransomware entry point before, and defenders learned of this bug from the attack, not the notice.

Unpatched on-premises deployments outside wealthy institutions face the longest exposure until they upgrade.

Sources: The Record