Security researchers have identified critical vulnerabilities in the Fiery Driver Updater, a software component embedded in print servers from major manufacturers such as Canon and Sharp. The flaws include hardcoded credentials and a lack of source file validation, which could allow attackers with prior access to exploit the updater for supply chain attacks and deliver malicious updates. These risks highlight the broader issue of printer infrastructure being an overlooked attack vector, with millions of devices potentially exposed due to poor update practices and weak security controls in printer management software.
In a separate but related incident, a small business experienced a severe cyberattack after their cloud-connected smart receipt printer, running a discontinued version of Android Things, began malfunctioning and ultimately served as a gateway for malware. This case underscores the real-world impact of insecure printer devices and the dangers posed by outdated or poorly secured embedded operating systems in IoT hardware. Both findings emphasize the urgent need for organizations to treat printers and their associated software as critical components of their security posture.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
BankInfoSecurity reported vulnerabilities in printer driver updater mechanisms that could allow poisoned or malicious updates to be delivered. The reference indicates public disclosure of the flaws but provides no additional earlier event dates in the provided content.
An OSINT Team Blog report described a case in which a low-cost smart printer was implicated in a security incident that severely affected a local business. The available reference provides no further dated incident details beyond the article publication.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.