Two recent PaperCut NG/MF vulnerabilities have been exploited in AI-powered attacks that hit hundreds of organizations worldwide, GreyNoise reports.
Tracked as CVE-2026-82078 and CVE-2026-81578, the security defects were disclosed on August 27 as zero-days and patched the next day.
They can allow remote unauthenticated attackers to bypass authentication and execute arbitrary code on vulnerable PaperCut NG/MF instances.
Several days later, WatchTowr threat intelligence head Jake Knott warned that the activity around the two vulnerabilities had been intensifying. Knott believed at the time that initial access brokers were likely behind the exploitation.
This week, threat intelligence firm GreyNoise revealed that a Russian-speaking threat actor has used AI to build, test, and deploy exploits against 440 PaperCut NG/MF deployments.
The threat actor targeted the vulnerable PaperCut instances of 395 organizations in 48 countries for remote code execution (RCE) and credential harvesting.
“There are other real victims that could not be attributed to a named organization. The adversary did explicitly attempt to avoid targeting entities in 28 identified countries; however, our observed victimology shows the attempted restraint failed in some instances,” GreyNoise says.
The use of AI to orchestrate the campaign allowed the threat actor to compromise some environments in minutes and even seconds. The attacker’s success was not even across all organizations, with domain admin achieved against only 12 victim organizations.
“It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their access to achieve follow-on objectives such as data theft or ransomware deployment,” GreyNoise notes.
The threat intelligence firm observed three attack paths across the campaign: harvested LSASS process memory and registry secrets from hosts that were domain members, mounted NoPac attacks against unpatched instances, and added a new account to Domain Admins if the host was a Domain Controller.
According to GreyNoise, the attackers performed credential harvesting against 280 of the compromised hosts, exfiltrated secrets from 137 of them, and gained domain admin privileges in 12 instances.
Of the 440 compromised deployments, 204 belonged to organizations in the education sector. Dozens of entities in the retail/professional services, real estate/hospitality, IT/MSP, non-profit/charity, library, and manufacturing/utilities sectors were hit as well.
Related: Critical NetScaler Vulnerability Exploited in Attacks
Related: Organizations Warned of Cisco Secure FMC Exploitation
Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
