PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Reported exploitedPaperCut NGRussian-speaking cyber actor (unspecified)PaperCut MFOur summary
A suspected Russian-speaking threat actor has leveraged hundreds of autonomous AI agents to compromise over 440 instances of PaperCut NG and PaperCut MF across 395 organizations. The attack chain exploits a combination of authentication bypass and remote code execution vulnerabilities, specifically CVE-2026-81578 and CVE-2026-82078, primarily targeting educational institutions in North America, Europe, and Oceania. Investigations by Blackpoint Cyber and GreyNoise revealed that the actor utilized OpenAI Codex and DeepSeek models alongside standard offensive tools to automate vulnerability research, target selection, and post-exploitation activities, achieving full domain administrator access on some networks within minutes. Administrators should verify patch levels for both CVEs immediately and monitor for indicators of compromise related to registry collection and Metasploit payloads.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.