<?xml version="1.0" encoding="UTF-8"?><feed
	xmlns="http://www.w3.org/2005/Atom"
	xmlns:thr="http://purl.org/syndication/thread/1.0"
	xml:lang="en-US"
	>
	<title type="text">HP LaserJet printer vulnerability: what you need to know &#8211; The Verge</title>
	<subtitle type="text">The Verge is about technology and how it makes us feel. Founded in 2011, we offer our audience everything from breaking news to reviews to award-winning features and investigations, on our site, in video, and in podcasts.</subtitle>

	<updated>2011-12-24T20:18:01+00:00</updated>

	<link rel="alternate" type="text/html" href="https://www.theverge.com/2011/11/29/2596970/hp-laserjet-printer-vulnerability" />
	<id>https://www.theverge.com/rss/stream/2361011</id>
	<link rel="self" type="application/atom+xml" href="https://www.theverge.com/rss/stream/2361011" />

	<icon>https://platform.theverge.com/wp-content/uploads/sites/2/2025/01/verge-rss-large_80b47e.png?w=150&amp;h=150&amp;crop=1</icon>
		<entry>
			
			<author>
				<name>Chris Welch</name>
			</author>
			
			<title type="html"><![CDATA[HP releases firmware fix for laserjet printer exploit]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/2011/12/24/2659385/hp-firmware-fix-laserjet-vulnerability" />
			<id>https://www.theverge.com/2011/12/24/2659385/hp-firmware-fix-laserjet-vulnerability</id>
			<updated>2011-12-24T15:18:01-05:00</updated>
			<published>2011-12-24T15:18:01-05:00</published>
			<category scheme="https://www.theverge.com" term="Verge Archives" />
							<summary type="html"><![CDATA[Give HP kudos for timeliness: less than a month after Columbia University researchers shared a worrisome lack of security surrounding firmware updates on the company's line of laserjet printers, a fix is now available for affected models. If you'll recall, Ang Cui and Salvatore Stolfo made headlines by revealing that attaching a virus to a [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="HP LaserJet" data-portal-copyright="" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/chorus/uploads/chorus_asset/file/13896356/HP_LaserJet_ProP1606dn_copy.1419963959.jpeg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	HP LaserJet	</figcaption>
</figure>
<p>Give <a class="sbn-auto-link" href="http://www.theverge.com/products/brands/hp/36">HP</a> kudos for timeliness: less than a month after Columbia University researchers <a href="http://www.theverge.com/2011/11/29/2596970/hp-laserjet-printer-vulnerability">shared a worrisome lack of security</a> surrounding firmware updates on the company's line of laserjet printers, a fix is now available for affected models. If you'll recall, Ang Cui and Salvatore Stolfo made headlines by revealing that attaching a virus to a print job on a vulnerable device could provide full access to an intruder, allowing sensitive content to be intercepted and even giving those with the most malicious of intent a way to overheat the fuser within. For its part, HP steadfastly denied the possibility of fire or an explosion, assuring consumers  …</p>
<p><a href="https://www.theverge.com/2011/12/24/2659385/hp-firmware-fix-laserjet-vulnerability">Read the full story at The Verge.</a></p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Thomas Ricker</name>
			</author>
			
			<title type="html"><![CDATA[HP confirms LaserJet vulnerability, promises firmware fix]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/2011/11/29/2596863/hp-confirms-laserjet-vulnerability-firmware-fix-in-development" />
			<id>https://www.theverge.com/2011/11/29/2596863/hp-confirms-laserjet-vulnerability-firmware-fix-in-development</id>
			<updated>2011-11-29T15:36:34-05:00</updated>
			<published>2011-11-29T15:36:34-05:00</published>
			<category scheme="https://www.theverge.com" term="Verge Archives" />
							<summary type="html"><![CDATA[HP just issued a statement saying it "refutes inaccurate claims" made in today's MSNBC report detailing a vulnerability in LaserJet printers that was exploited by Columbia University researchers Ang Cui and Salvatore Stolfo. HP confirms that there's a potential vulnerability in LaserJet printers and promises a firmware update to "mitigate" the issues, but the company [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="HP LaserJet" data-portal-copyright="" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/chorus/uploads/chorus_asset/file/13886796/HP_LaserJet_ProP1606dn_copy.1419963357.jpeg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	HP LaserJet	</figcaption>
</figure>
<p>HP just issued a statement saying it "refutes inaccurate claims" made in today's <a href="http://www.theverge.com/2011/11/29/2595691/hp-laserjet-printers-pose-massive-security-risk-say-columbia"><em>MSNBC</em> report detailing a vulnerability in LaserJet printers</a> that was exploited by Columbia University researchers Ang Cui and Salvatore Stolfo. HP confirms that there's a potential vulnerability in LaserJet printers and promises a firmware update to "mitigate" the issues, but the company also says that "no customer has reported unauthorized access" and that it's not possible to set a fire by exploiting the vulnerability because of the printer's thermal control hardware.</p>
<p>What's more, while HP says it's possible for a specially formatted print job from Linux of M …</p>
<p><a href="https://www.theverge.com/2011/11/29/2596863/hp-confirms-laserjet-vulnerability-firmware-fix-in-development">Read the full story at The Verge.</a></p>
						]]>
									</content>
			
					</entry>
			<entry>
			
			<author>
				<name>Thomas Ricker</name>
			</author>
			
			<title type="html"><![CDATA[HP LaserJet printers pose massive security risk, say Columbia University researchers]]></title>
			<link rel="alternate" type="text/html" href="https://www.theverge.com/2011/11/29/2595691/hp-laserjet-printers-pose-massive-security-risk-say-columbia" />
			<id>https://www.theverge.com/2011/11/29/2595691/hp-laserjet-printers-pose-massive-security-risk-say-columbia</id>
			<updated>2011-11-29T07:31:12-05:00</updated>
			<published>2011-11-29T07:31:12-05:00</published>
			<category scheme="https://www.theverge.com" term="HP" /><category scheme="https://www.theverge.com" term="Tech" />
							<summary type="html"><![CDATA[MSNBC is reporting a security flaw that could affect millions of HP LaserJet printers. According to Ang Cui and Salvatore Stolfo of Columbia University, the issue stems from the fact that the HP LaserJet printers tested do not require a signature or certificate to identify the source of remote software updates. Knowing this, Cui and [&#8230;]]]></summary>
			
							<content type="html">
											<![CDATA[

						
<figure>

<img alt="" data-caption="HP laserjet" data-portal-copyright="" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/chorus/uploads/chorus_asset/file/13886566/201502.1419963343.jpeg?quality=90&#038;strip=all&#038;crop=0,0,100,100" />
	<figcaption>
	HP laserjet	</figcaption>
</figure>
<p><em>MSNBC</em> is <a target="_blank" href="http://redtape.msnbc.msn.com/_news/2011/11/29/9076395-exclusive-millions-of-printers-open-to-devastating-hack-attack-researchers-say">reporting a security flaw</a> that could affect millions of HP LaserJet printers. According to Ang Cui and Salvatore Stolfo of Columbia University, the issue stems from the fact that the <a class="sbn-auto-link" href="http://www.theverge.com/products/brands/hp/36">HP</a> LaserJet printers tested do not require a signature or certificate to identify the source of remote software updates. Knowing this, Cui and Stolfo are able to exploit the fact that every time a LaserJet accepts a new job it checks for an included software update.</p>
<p>One demonstration by the duo involved infecting a printer through a virus-laden print job. A tax return sent to the infected printer was then surreptitiously forwarded to a remote computer po …</p>
<p><a href="https://www.theverge.com/2011/11/29/2595691/hp-laserjet-printers-pose-massive-security-risk-say-columbia">Read the full story at The Verge.</a></p>
						]]>
									</content>
			
					</entry>
	</feed>
