🔒

Security

Harden your printers against modern threats: RAT malware, driver vulnerabilities, unsecured SMB shares, and printer-based phishing. Expert guidance for SMBs.

Showing 16 articles

Security

Blurred PDF Invoices With QR Codes: HP Wolf's Quishing Warning

On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.

2026-09-28
6 min read
Read More
Security

September 2026 Patch Tuesday: Critical Windows Print Flaw Fixed

Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.

2026-09-14
7 min read
Read More
Security

PaperCut NG/MF Zero-Days Exploited: What Offices Should Check Now

On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.

2026-08-31
7 min read
Read More
Security

Sharp and Toshiba Copier Flaws: Turn On User Authentication

On July 31, Sharp and Toshiba Tec disclosed three flaws in their office MFPs, and NIST's vulnerability database published them August 3. The most practical one: affected models built for markets outside Japan, including the US, shipped with user authentication turned off. Turn it on, and ask your dealer for the firmware that fixes the other two.

2026-08-10
8 min read
Read More
Security

Critical Print Spooler Flaw Fixed in July 2026 Patch Tuesday

Microsoft's record July 14, 2026 Patch Tuesday fixed CVE-2026-58608, a Critical Windows Print Spooler flaw that any logged-in, low-privilege user could exploit over the network. It wasn't exploited at release. Confirm July's update is installed on every PC, especially the one that shares your printers, and protect staff accounts from phishing.

2026-07-20
7 min read
Read More
Security

HP DeskJet 2800 Flaw Leaks Wi-Fi Direct Passwords: What to Do

On July 6, 2026, CERT/CC disclosed CVE-2026-13753: HP DeskJet 2800 series printers on firmware TBP1CN2612AR or earlier let anyone on the network read sensitive settings, including the Wi-Fi Direct password in plain text, without logging in. No fix was available at disclosure. Find these printers, turn off Wi-Fi Direct and SNMP if unused, and keep them off guest Wi-Fi.

2026-07-13
6 min read
Read More

Stay Updated with Industry Insights

Get valuable printer industry insights, cost-saving tips, and practical business advice delivered monthly. No spam, ever.

By subscribing, you agree to our Privacy Policy

Protected by Cloudflare Turnstile