PaperCut Flaws Exploited in AI-Powered Attacks
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- PaperCut
- Reported by
- 1 outlet
Two recent PaperCut NG/MF vulnerabilities have been exploited in AI-powered attacks that hit hundreds of organizations worldwide, GreyNoise reports.
Tracked as CVE-2026-82078 and CVE-2026-81578, the security defects were disclosed on August 27 as zero-days and patched the next day.
They can allow remote unauthenticated attackers to bypass authentication and execute arbitrary code on vulnerable PaperCut NG/MF instances.
Several days later, WatchTowr threat intelligence head Jake Knott warned that the activity around the two vulnerabilities had been intensifying. Knott believed at the time that initial access brokers were likely behind the exploitation.
This week, threat intelligence firm GreyNoise revealed that a Russian-speaking threat actor has used AI to build, test, and deploy exploits against 440 PaperCut NG/MF deployments.
The threat actor targeted the vulnerable PaperCut instances of 395 organizations in 48 countries for remote code execution (RCE) and credential harvesting.
Advertisement. Scroll to continue reading.
“There are other real victims that could not be attributed to a named organization. The adversary did explicitly attempt to avoid targeting entities in 28 identified countries; however, our observed victimology shows the attempted restraint failed in some instances,” GreyNoise says.
The use of AI to orchestrate the campaign allowed the threat actor to compromise some environments in minutes and even seconds. The attacker’s success was not even across all organizations, with domain admin achieved against only 12 victim organizations.
“It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their access to achieve follow-on objectives such as data theft or ransomware deployment,” GreyNoise notes.
The threat intelligence firm observed three attack paths across the campaign: harvested LSASS process memory and registry secrets from hosts that were domain members, mounted NoPac attacks against unpatched instances, and added a new account to Domain Admins if the host was a Domain Controller.
According to GreyNoise, the attackers performed credential harvesting against 280 of the compromised hosts, exfiltrated secrets from 137 of them, and gained domain admin privileges in 12 instances.
Of the 440 compromised deployments, 204 belonged to organizations in the education sector. Dozens of entities in the retail/professional services, real estate/hospitality, IT/MSP, non-profit/charity, library, and manufacturing/utilities sectors were hit as well.
Related: Critical NetScaler Vulnerability Exploited in Attacks
Related: Organizations Warned of Cisco Secure FMC Exploitation
Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
Reproduced in full under licence from SecurityWeek. © SecurityWeek. Written by Ionut Arghire.
Coverage
One outlet has carried this so far.
2026-09-11 08:18 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
The Hacker News · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16