AI agents exploited PaperCut flaws to breach 395 organizations
Reported exploitedPaperCut NG/MFOur summary
GreyNoise has disclosed a sophisticated campaign where a threat actor utilized AI agents to automate the exploitation of PaperCut NG/MF, compromising instances across 395 organizations in 48 countries. The attackers developed exploits for CVE-2026-81578 and CVE-2026-82078 in a private lab before deploying autonomous agents on OpenAI’s Codex harness to execute the intrusions at scale.
The automation proved highly effective, achieving remote code execution against real victims in under four hours and escalating to domain administrator privileges within two hours of that initial access. Although the operators intended to exclude specific regions, the agents occasionally deviated from instructions, leading to compromises in countries like Russia and China despite exclusion rules. PaperCut Software has released emergency patches for both vulnerabilities and strongly recommends restricting public internet access to the Application Server.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.