Vulnerabilities

PaperCut Flaws Exploited in AI-Powered Attacks

A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

PaperCut zero-day exploited

Two recent PaperCut NG/MF vulnerabilities have been exploited in AI-powered attacks that hit hundreds of organizations worldwide, GreyNoise reports.

Tracked as CVE-2026-82078 and CVE-2026-81578, the security defects were disclosed on August 27 as zero-days and patched the next day.

They can allow remote unauthenticated attackers to bypass authentication and execute arbitrary code on vulnerable PaperCut NG/MF instances.

Several days later, WatchTowr threat intelligence head Jake Knott warned that the activity around the two vulnerabilities had been intensifying. Knott believed at the time that initial access brokers were likely behind the exploitation.

This week, threat intelligence firm GreyNoise revealed that a Russian-speaking threat actor has used AI to build, test, and deploy exploits against 440 PaperCut NG/MF deployments.

The threat actor targeted the vulnerable PaperCut instances of 395 organizations in 48 countries for remote code execution (RCE) and credential harvesting.

Advertisement. Scroll to continue reading.

“There are other real victims that could not be attributed to a named organization. The adversary did explicitly attempt to avoid targeting entities in 28 identified countries; however, our observed victimology shows the attempted restraint failed in some instances,” GreyNoise says.

The use of AI to orchestrate the campaign allowed the threat actor to compromise some environments in minutes and even seconds. The attacker’s success was not even across all organizations, with domain admin achieved against only 12 victim organizations.

“It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their access to achieve follow-on objectives such as data theft or ransomware deployment,” GreyNoise notes.

The threat intelligence firm observed three attack paths across the campaign: harvested LSASS process memory and registry secrets from hosts that were domain members, mounted NoPac attacks against unpatched instances, and added a new account to Domain Admins if the host was a Domain Controller.

According to GreyNoise, the attackers performed credential harvesting against 280 of the compromised hosts, exfiltrated secrets from 137 of them, and gained domain admin privileges in 12 instances.

Of the 440 compromised deployments, 204 belonged to organizations in the education sector. Dozens of entities in the retail/professional services, real estate/hospitality, IT/MSP, non-profit/charity, library, and manufacturing/utilities sectors were hit as well.

Related: Critical NetScaler Vulnerability Exploited in Attacks

Related: Organizations Warned of Cisco Secure FMC Exploitation

Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Related Content

Vulnerabilities

Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.

Vulnerabilities

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

Malware & Threats

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

Mobile & Wireless

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.

Vulnerabilities

The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.

Vulnerabilities

The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.

ICS/OT

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Vulnerabilities

The security defect allows remote attackers to bypass authentication through argument bearer manipulation.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version