AI-Powered Attack Exploited PaperCut Flaws to Hack 395 Organizations
GreyNoise said the campaign reached 440 compromised instances in 48 countries and hit 204 education victims after emergency PaperCut patches.
- An unknown attacker used hundreds of AI agents to exploit PaperCut vulnerabilities, compromising at least 440 instances across 395 organizations in 48 countries, according to threat-intel firm GreyNoise.
- The campaign, launched on August 31, utilized OpenAI Codex and DeepSeek models to automate exploitation of two PaperCut flaws after emergency patches for CVE-2026-81578 and CVE-2026-82078 were issued on August 28.
- Schools suffered the most with 204 victims, while American targets dominated the compromise count. GreyNoise noted "multiple-day delays" between gaining initial access and achieving domain admin, though some intrusions occurred in just five minutes.
- GreyNoise attributes the intrusions to a "likely Russian-speaking" criminal who instructed agents to avoid entities in 28 countries, including Russia and Several Commonwealth of Independent States nations, though agents did not always comply.
- Analysts warn that fundamental hardening of environments remains necessary against AI-enabled threats. It remains unclear whether the attacker intends personal nefarious activities or plans to sell compromised access to other groups.
10 Articles
10 Articles
AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]
An automated cyber campaign took advantage of two recent PaperCut flaws to engage at least 395 organizations in 48 countries. GreyNoise attributes the operation to a likely Russian-speaking attacker who employed hundreds of AI agents, although some ended up attacking targets they should avoid.
AI Agents Compromised 440 PaperCut Servers, Researchers Say
A threat intelligence firm says it watched a Russian-speaking attacker turn hundreds of AI agents loose on a print management platform and compromise 440 servers in 48 countries — including 11 organizations in 26 seconds. It is the most vivid account yet of an autonomous intrusion campaign. It is also, so far, a single-source story that the vendor at the center of it has pointedly declined to endorse. GreyNoise published the report on Sept. 9, d…
AI-powered attack exploited PaperCut flaws to hack 395 organizations | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker - National Cyber Security Consulting
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. The agents were tasked with building, testing, and refining exploits for CVE-2026-81578 and CVE-2026-82078, both security flaws affecting PaperCut Software and flagged as actively exploited earlier this month. Attack and threat intelligence company GreyNoise […] Thank you for subscr…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium







