The print server held the LDAP bind credentials. That is what they came for
2026-09-07Security
Arctic Wolf has published what attackers do after exploiting the two PaperCut zero-days against schools and universities: create an account, dump the SAM hives, and grep the PaperCut config for the strings password, secret, ldap, bind and token. The print server is domain-joined and nobody's threat model has it on the list.