TWO recent PaperCut NG/MF vulnerabilities have been exploited in AI-powered attacks that hit hundreds of organisations worldwide, GreyNoise reports. Tracked as CVE-2026-82078 and CVE-2026-81578, the flaws were disclosed on 27 August as zero-days and patched the following day. The defects allow remote unauthenticated attackers to bypass authentication and execute arbitrary code on vulnerable PaperCut NG/MF instances.
GreyNoise notes that a Russian-speaking threat actor used AI to build, test and deploy exploits against 440 PaperCut deployments, compromising 395 organisations in 48 countries for remote code execution and credential harvesting.
GreyNoise describes three attack paths observed in the campaign: harvested LSASS process memory and registry secrets from domain-member hosts, mounted NoPac attacks against unpatched instances, and the addition of a new account to Domain Admins if the host was a Domain Controller. The firm also details operational metrics: credential harvesting against 280 compromised hosts, exfiltration of secrets from 137, and domain admin privileges gained in 12 instances.
Of the 440 compromised deployments, 204 belonged to organisations in the education sector; other sectors affected included retail/professional services, real estate/hospitality, IT/MSP, non-profit/charity, libraries and manufacturing/utilities. GreyNoise cautions that some victims could not be attributed to a named organisation, and while initial access brokers may have played a role, AI orchestration accelerated compromise to minutes or seconds in some cases. Security teams are noted as assessing whether access would be used for data theft or ransomware.