AI-Powered Cyberattack Exploits PaperCut Vulnerabilities to Breach 395 Organizations Globally

In a chilling display of AI-driven cybercrime, a suspected Russian-speaking attacker utilized an autonomous army of AI agents. These agents exploited critical vulnerabilities in PaperCut print management software, resulting in the breach of 395 organizations across 48 countries. The threat intelligence firm, GreyNoise, unveiled these findings on September 9.

The cyberattack campaign initiated on August 31, compromising at least 440 PaperCut NG/MF server instances. The attacker ingeniously combined OpenAI’s Codex and a DeepSeek model with standard offensive tools. This combination enabled the building, testing, and deployment of exploits autonomously.

GreyNoise discovered that the operator transitioned from an empty workspace to executing code on a real victim in under four hours. At its peak efficiency, the AI agents infiltrated 11 organizations within a mere 26 seconds.

The attacker harvested credentials from 280 victims, obtained OS or domain secrets from 147, and gained administrator privileges at 12 organizations. The campaign exploited two critical flaws: CVE-2026-81578 (an authentication bypass, CVSS 8.8) and CVE-2026-82078 (an unsafe class-loading bug enabling remote code execution, CVSS 9.4).

Approximately half of all breached organizations were in the education sector, including schools and universities. PaperCut, whose software is utilized by over 100 million users across 70,000 organizations worldwide, has since issued security maintenance updates to replace earlier emergency patches. System administrators are strongly urged to apply these updates immediately.

Source: BleepingComputer — AI-powered attack exploited PaperCut flaws to hack 395 organizations

Move to the category:

Leave a Reply

Your email address will not be published. Required fields are marked *