thehackernews.com 10 Sept 2026, 11:41 UTC

AI-Driven Campaign Exploits PaperCut Flaws Across 440 Instances

CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

A Russian-speaking cyber actor is said to have used artificial intelligence to weaponise vulnerabilities in PaperCut NG/MF, exploiting CVE-2026-81578 and CVE-2026-82078 to breach hundreds of instances. Independent researchers track activity from the IP 45.142.193[.]132, which has recently featured in port scanning and brute‑force activity linked to PaperCut exploitation.

The campaign appears opportunistic, focusing on the education sector and affecting 440+ PaperCut MF/NG instances across 395 identified victim organisations in 48 countries, with notable impact in the United States, United Kingdom, and several European nations.

Evidence from GreyNoise and Blackpoint points to a staged, AI‑driven workflow. After gaining remote code execution and harvesting credentials in a self‑built lab environment (which included an Active Directory server and vulnerable PaperCut instances), the actor deployed hundreds of AI Agents powered by OpenAI Codex and a DeepSeek model, alongside publicly available offensive tools such as Mimikatz, SharpHound, Certipy, Rubeus and Impacket.

The attackers used a lab‑to‑production loop to prioritise targets, filter live PaperCut systems, and orchestrate post‑exploitation actions across diverse environments. Observed post‑exploitation activity included registry hive collection, Java payloads for Metasploit/Meterpreter, and commands to identify hosts, users, processes and configuration data.

While the initiative demonstrates AI’s role in accelerating exploitation and scale, the ultimate objective—data theft, ransomware, or other follow‑on goals—remains unclear.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline