Security research where the paper path becomes an attack path.

Coordinated vulnerability disclosure and technical research into the infrastructure nobody audits. Starting with the printers.

Every enterprise network has a layer that runs with high privilege, handles things the business cares about, and has sat untouched since the day it was installed. Directories, messaging, identity, print. Nobody audits it because nobody owns it, and the people who could find the problems are busy keeping it running.

Print and scan is where this started — a product line nobody was looking at. It won’t be the last.

Service-manual diagram showing a sheet leaving the expected paper path and crossing a security boundary to become a CVE document.
FIG. 01 · ABNORMAL FEED CONDITIONPaper path: compromised

Published disclosures

Unauthenticated paths into privileged infrastructure. Each one was reported to the vendor first and published alongside a confirmed fix.

A few web calls. Then a little poking around.

Printer services rarely receive the same scrutiny as the systems around them. A few ordinary web requests can expose enough structure to start asking questions. Poking leads to prodding, and prodding sometimes uncovers an API endpoint that never asks who is calling.

That forgotten surface can sit beside sensitive documents and privileged workflows, where one overlooked endpoint may open paths to data theft, forgery, impersonation, or deeper system access.

See where the questions led