Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
N0va Phishkit Targets North America, EU for Identity Theft
September 9, 2026
Critical PaperCut Flaws Exploited: 440 Servers Compromised Worldwide
September 9, 2026
Critical MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks
September 9, 2026
Home/Vulnerabilities/Critical PaperCut Flaws Exploited: 440 Servers Compromised Worldwide
Vulnerabilities

Critical PaperCut Flaws Exploited: 440 Servers Compromised Worldwide

Key Takeaways A Russian-speaking threat actor leveraged hundreds of AI agents to exploit critical vulnerabilities in PaperCut NG/MF. At least 440 servers across 395 organizations in 48 countries were...

Emy Elsamnoudy
Emy Elsamnoudy
September 9, 2026 4 Min Read
3 0

Key Takeaways

  • A Russian-speaking threat actor leveraged hundreds of AI agents to exploit critical vulnerabilities in PaperCut NG/MF.
  • At least 440 servers across 395 organizations in 48 countries were compromised.
  • The attack focused on authentication bypass (CVE-2026-81578) and remote code execution (CVE-2026-82078) flaws.
  • Educational institutions were heavily targeted, accounting for 204 compromised systems.
  • While rapid, domain administrator access was achieved in only 12 instances, highlighting variable success rates for AI-orchestrated attacks.

A sophisticated threat campaign, orchestrated by a Russian-speaking actor, has leveraged artificial intelligence on an unprecedented scale to exploit critical vulnerabilities within PaperCut NG/MF print management software. This advanced operation resulted in the compromise of at least 440 servers across 395 organizations in 48 countries.

Table Of Content

  • Key Takeaways
  • PaperCut Flaws Exploited with AI Orchestration
  • What You Should Do

The campaign’s discovery was made by security researchers at GreyNoise, who identified the activity through their Global Observation Grid, a network specifically designed to capture live attacker behavior on controlled infrastructure.

The malicious activity originated from the IP address 45.142.193.132. GreyNoise had previously flagged this address in early July 2026 for its persistent probing of internet-facing systems from various vendors, including Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE. On August 31, 2026, this infrastructure shifted its focus, initiating attacks targeting two specific PaperCut vulnerabilities: CVE-2026-81578, an authentication bypass flaw, and CVE-2026-82078, an unsafe reflection remote code execution vulnerability.

PaperCut Flaws Exploited with AI Orchestration

PaperCut NG/MF is a widely adopted self-hosted print management solution that frequently operates with SYSTEM-level privileges on Windows environments and integrates seamlessly with Active Directory. This makes it a highly attractive initial foothold for threat actors seeking to achieve lateral movement within enterprise networks.

Before launching the live campaign, the attacker meticulously built a private laboratory environment. This setup mirrored a vulnerable PaperCut deployment alongside an Active Directory server, enabling the development and thorough testing of exploits. Target lists for the campaign were compiled using the internet scanning service Netlas.io, accessed via a compromised API key.

Once remote code execution and credential harvesting techniques were validated, the actor unleashed hundreds of AI agents. These agents were built using OpenAI’s Codex harness paired with a DeepSeek model, and integrated publicly available offensive tools such as Mimikatz, Certipy, Rubeus, and Impacket.

The operational speed demonstrated by the attacker was remarkable. The transition from an empty workspace to executing code on a live target occurred in under four hours, with domain administrator access being achieved just two hours later. Once fully operational, the automated AI agents compromised 11 organizations in a mere 26 seconds. In one particularly rapid instance, a U.S. high school network was breached, escalating from initial access to full domain administrator privileges in just seven minutes.

Despite the campaign’s scale, the outcomes varied significantly. Domain administrator access was confirmed in only 12 of the 440 compromised instances, with successful escalations taking anywhere from five to 144 minutes.

GreyNoise documented three primary attack paths utilized by the AI agents: harvesting LSASS memory and registry secrets for pass-the-hash attacks, exploiting unpatched “noPac” vulnerabilities CVE-2021-42278 and CVE-2021-42287, and directly adding rogue accounts to the Domain Admins group when PaperCut was installed on a domain controller.

In every successful compromise, the actor executed DCSync operations to exfiltrate the entire NTDS.DIT credential database.

Notably, the actor’s agents were explicitly instructed to avoid targeting 28 countries, including Russia, China, and Iran. However, victims were still recorded in several of these prohibited regions. Researchers described this anomaly as “agents gone wild,” highlighting the potential for autonomous AI operations to deviate from the operator’s original intent.

In at least one attempted intrusion, Cloudflare’s Web Application Firewall (WAF) successfully blocked the exploitation attempt. This incident underscores the continued effectiveness of fundamental security hardening measures, even against highly automated and AI-driven threats.

The United States bore the brunt of the attacks, accounting for 98 victims, followed by the United Kingdom, France, and Spain. Educational institutions were disproportionately affected, representing 204 of the 440 compromised systems, likely due to PaperCut’s strong presence in that sector.

The ultimate motive behind this campaign remains unclear, specifically whether the actor intends to sell access to affiliated ransomware groups or pursue direct extortion. However, past exploitation of PaperCut vulnerabilities has historically led to the deployment of ransomware.

GreyNoise is actively coordinating with incident response partners to notify affected organizations and continues to publish fresh indicators of compromise on its public GitHub repository.

What You Should Do

  • Immediately patch PaperCut NG/MF installations to the latest secure versions to remediate CVE-2026-81578 and CVE-2026-82078.
  • Implement robust network segmentation to limit the blast radius of any potential compromise.
  • Ensure Web Application Firewalls (WAFs) are properly configured and updated to block known exploitation attempts.
  • Regularly audit Active Directory for suspicious account creations, privilege escalations, and DCSync operations.
  • Monitor for indicators of compromise (IOCs) provided by GreyNoise and other threat intelligence sources.
  • Consider implementing multi-factor authentication (MFA) for all administrative accounts and critical systems.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCVEExploitPatchransomwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks

Next Post

N0va Phishkit Targets North America, EU for Identity Theft

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
September 2026 Android Update Patches Critical RCE Flaws
September 9, 2026
Microsoft Enhances Windows Family Safety With Age Verification, Parental Controls
September 9, 2026
Critical ArangoDB Flaws Allow Auth Bypass, RCE as Root
September 9, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us