The Perils of Printing in Public
# The Perils of Printing in Public
There is a particular kind of silence that descends upon an IT department when they realise the breach didn't come through the firewall, the email gateway, or a sophisticated phishing campaign targeting the CFO. Instead, it came through the printer management software.
PaperCut has spent the last few days issuing emergency patches for two critical vulnerabilities in its NG and MF software. The technical details are unpleasant: attackers can chain these flaws to achieve unauthenticated remote code execution. In plain English, if you haven't patched, someone from the outside can tell your print server to do almost anything they like.
What interests me isn't the exploit itself, but the rhythm of the disclosure. PaperCut has already had to release a second emergency patch because the first didn't quite do the job. This is the slow machinery of vendor remediation in real-time. We are told that "emergency" patches are the solution, but for the admin tasked with deploying them across four hundred disparate office locations over a weekend, an emergency patch is simply a request for more unpaid overtime.
The industry loves to talk about the 'attack surface', as if it were a map they could fold up and put in a pocket. It isn't. It is every single forgotten piece of middleware that was installed in 2019 by a contractor who has since moved to a different time zone. The fact that printer software—something most people treat with the same level of scrutiny as a stapler—can provide a direct path to root access is a stark reminder that we are only as secure as our most boring asset.
It's a recurring theme this week. Looking at the wire, there have been 380 stories about data breaches in the last seven days alone. The noise is deafening, but the signal is clear: the gaps are rarely in the flashy new tech and almost always in the plumbing.
Speaking of plumbing, let us consider the scale of the recent confirmation from a UK airport operator. They've admitted to a breach affecting 8.7 million customers.
From a technical perspective, it's a disaster. From a regulatory perspective, it is a paperwork nightmare that would make a seasoned Brussels bureaucrat weep with joy. Under the UK-GDPR, the requirement to notify individuals without undue delay becomes an exercise in logistics when you are dealing with nearly nine million people. The sheer volume of communication required here isn't just a cost; it's a liability. If you send nine million emails and 10% of them land in spam or contain a typo in the notification link, you've simply created a new vector for phishing.
The second-order effect here is where the real damage lies. This isn't just about leaked names or email addresses. Airport data often contains travel patterns, flight numbers, and passport details. For the high-net-worth individuals or government officials who transit through these hubs, this is a goldmine for social engineering. An attacker doesn't need to hack your laptop if they can send you a perfectly timed email about your specific flight from Heathrow to Singapore, referencing your actual booking date.
The airport will likely claim they are "working closely with the ICO," which is regulatory shorthand for "we hope the fine isn't large enough to affect the quarterly dividend."
I suspect the fine won't be the problem. The problem will be the audit. Once the Information Commissioner’s Office decides to look at how 8.7 million records were stored, they will find every single shortcut taken over the last five years. That is where the actual cost resides—not in the headline penalty, but in the forced expenditure of a total infrastructure overhaul that should have happened three years ago.
Then we have the DNA testing breach. We don't have a final tally on the exact number of records yet, but it is in the millions.
This is where I take a firm position: our current regulatory framework for genetic data is hopelessly inadequate. We treat a leaked genome roughly the same as we treat a leaked credit card number. You can cancel a credit card. You cannot cancel your DNA.
When a password is stolen, you change it. When your genetic markers are dumped onto a forum, that information is permanent for you and every single one of your biological relatives. We have created a commercial industry around "ancestry" and "health insights" without any meaningful law governing the long-term stewardship of that data.
In Oslo, there has been some quiet discussion about stricter biometric sovereignty, but the rest of the world is lagging. The objection usually raised is that strict regulations stifle medical innovation. This is a convenient argument for the companies collecting the data, but it ignores the reality that once the data is leaked, the "innovation" belongs to whoever is hosting the leak site.
The irony is palpable when you look at the sector rankings for the week. Government is currently the most targeted sector, sitting at #1 of 12 with 231 stories. These agencies are tasked with regulating the very companies that are failing so spectacularly.
We are seeing a pattern where the "emergency" response has become the standard operating procedure. We patch the printer, we notify the millions of airport passengers, and we shrug at the loss of genetic data, all while the government agencies responsible for oversight are themselves fighting off ransomware groups like Qilin.
The question we should be asking is why we continue to trust a "patch-and-pray" model for critical infrastructure. If a bridge were found to have two critical structural flaws that allowed it to collapse without warning, we wouldn't just apply a "patch" of concrete and hope for the best; we would close the bridge until the design was proven safe.
In software, we just keep the bridge open and send out an email at 4:00 PM on a Friday telling everyone to be careful while they cross.
I'll be watching to see if the UK airport operator mentions "third-party vendors" in their next update. It is the classic move—shifting the blame downstream to a managed service provider who likely has a contract that limits their liability to the cost of one month's service.
It’s an elegant way to ensure that no one is actually responsible for those 8.7 million people.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- ShinyHunters claims McKesson data breach exposing 284 million patients - CyberInsider Google News Security
- PaperCut warns of hackers using printer management software flaw in attacks The Record
- UK airport operator confirms data breach affecting 8.7 million customers - SC Media UK Google News Security
- Millions of patients warned after DNA testing data breach - Cybernews Google News Security
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication The Hacker News
- Airport Wi-Fi Data Breach Exposes Millions of Travelers: This Week in Scams - McAfee Google News Security
- Data breach hits 8.7 million customers at UK airports - BetaNews Google News Security
- PaperCut releases second emergency patch for exploited flaws BleepingComputer