Hundreds of AI Agents Help Attacker Exploit PaperCut Flaws Across 395 Organizations
Tech

Hundreds of AI Agents Help Attacker Exploit PaperCut Flaws Across 395 Organizations

TechNews Editorial
TechNews EditorialSep 13, 2026 · 3 min read
Share

An unknown attacker used hundreds of AI agents to exploit two PaperCut MF and NG bugs. The intrusions broke into at least 395 organizations. The victims concentrated in the US education sector, and the intrusions moved fast. In one case, an American high school went from initial access to domain admin in seven minutes.

These agents used OpenAI's Codex harness and a DeepSeek model. They allowed the miscreant to attack organizations at scale. Threat-intel firm GreyNoise traced the campaign's orchestration to 45.142.193.132 on August 31.

The adversary went from an empty workspace to first achieving remote code execution against a real victim in just under four hours. They reached first domain admin in an additional two hours. Once the full campaign launched, they compromised at least 11 organizations in 26 seconds, according to GreyNoise analysts.

The security provider attributes these intrusions to a likely Russian-speaking criminal. This actor used AI to develop exploits against the pair of PaperCut vulnerabilities disclosed just days earlier. On August 28, the print management software provider issued emergency fixes for CVE-2026-81578 and CVE-2026-82078. The company warned it was aware of confirmed customer incidents and treated the matter with the highest priority. The flaws affect PaperCut NG and MF, which are self-hosted Java web applications running with SYSTEM-level privileges on Windows by default.

PaperCut's CEO later stated that the first reported compromise arrived on August 27 and involved an education-sector firm. On Thursday, PaperCut published security maintenance releases replacing the earlier emergency fixes. By now, at least 440 instances hosted by 395 identified victim organizations across 48 countries have been compromised, per GreyNoise. Other real victims could not be attributed to a named organization.

The human attacker told the agents to avoid targeting entities in 28 countries. The top five excluded countries were Russia, China, Hong Kong, Thailand, and Iran. Several Commonwealth of Independent States countries are on the list, prompting GreyNoise to assess the criminal as likely Russian-speaking. It is typical for ransomware and cybercrime operations to expressly avoid attacking Russia and other CIS countries. Their governments often provide safe harbor for extortionists and financially motivated criminals, and local cops tend to ignore digital break-ins unless gangs infect in-country organizations.

However, the agents in the PaperCut attacks did not always follow these instructions. In some cases, they still hacked organizations based in countries on the do-not-hit list. It is currently uncertain why the attacker agents deviated, but it serves as an example of agents gone wild.

The US and the UK registered the highest victim counts at 98 and 59, respectively. Schools and other education-industry organizations proved by far the hardest hit with 204 victims. The second-ranked industry category recorded 51 victims, while retail, commercial, and professional services ranked third with 38 victims.

After using AI to develop exploits, achieve remote code execution, and harvest credentials in a self-hosted lab, the baddie set hundreds of AI agents loose on the open internet. These agents found and attacked public-facing, vulnerable instances. The campaign appears opportunistic, with the high concentration of US-based education targets likely attributable to the customer base of PaperCut NG and MF.

The attacker did not immediately start post-compromise actions with all victims. GreyNoise noted multiple-day delays between gaining initial access and achieving domain admin, driven solely by a lack of action by the adversary. The fastest time was five minutes, while the longest was 144 minutes.

It remains unclear if the criminal only plans to secure access and hand attacks off to affiliates, or use the access for follow-on nefarious activities. GreyNoise noted that Cloudflare's Web Application Firewall blocked the attacker in at least one case, showing that fundamental hardening of environments still matters against AI-enabled threats.

GreyNoise has tracked malicious use of the same IP address since early July. The IP has been used in attacks against internet-facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.

Newsletter

Get the best AI & tech news daily

A concise daily digest. Unsubscribe anytime.

We use your email only to send this newsletter.

Related Stories