AI-powered attack exploited PaperCut flaws to hack 395 organizations
Recorded: Sept. 10, 2026, 4 p.m.
| Original | Summarized |
AI-powered attack exploited PaperCut flaws to hack 395 organizations News Featured AdaptHealth confirms 4.1 million people exposed in July cyberattack Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Over 36,000 exposed Plex servers vulnerable to recent flaws New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers IDScan confirms breach tied to 153 million stolen driver’s licenses New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws The Top 4 Threats We Found by Investigating Every Alert for a Quarter Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityAI-powered attack exploited PaperCut flaws to hack 395 organizations AI-powered attack exploited PaperCut flaws to hack 395 organizations By Bill Toulas September 10, 2026 A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. Attack timelineSource: GreyNoise Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Related Articles: Actively Exploited Bill Toulas Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Sponsor Posts Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. Overdue a password health-check? Audit your Active Directory for free See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance. EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
An AI-powered attack was observed exploiting flaws in PaperCut NG/MF servers, leading to the compromise of at least 395 organizations across 48 countries. A threat actor, likely Russian-speaking, utilized hundreds of AI agents to orchestrate a global exploitation campaign targeting specific security vulnerabilities, namely CVE-2026-81578 and CVE-2026-82078, both of which were known to be actively exploited. The campaign leveraged advanced models such as OpenAI’s Codex and DeepSeek, combined with commodity offensive tools and the Netlas platform for target identification. These AI agents were responsible for developing, testing, and refining the necessary exploits. The operation commenced on August 31, integrating these tools to conduct rapid infiltration. The resulting compromise affected at least 440 PaperCut instances linked to the 395 distinct organizations. The attackers successfully harvested credentials from 280 victims, obtained operating system or domain secrets from 147 victims, and secured administrator privileges in 12 organizations. The victims were predominantly located in the education sector, with the United States being the most targeted country, followed by the United Kingdom, France, Spain, and Canada. The threat actor demonstrated an ability to execute attacks at tremendous speed, as noted by GreyNoise, achieving remote code execution against a victim in under four hours and gaining primary domain administrator access in just two hours in one instance. The post-exploitation activity involved several sophisticated attack paths observed by researchers. These included dumping Local Security Authority Subsystem Service memory and registry secrets from domain-joined PaperCut servers to facilitate a pass-the-hash attack against domain controllers. Another method involved exploiting environments still vulnerable to earlier flaws, such as CVE-2021-42278 and CVE-2021-42287, using the noPac attack. Furthermore, attackers achieved privilege escalation by directly adding newly created accounts to the Domain Admins group when PaperCut operated within a domain environment. In all scenarios, the attackers employed the DCSync post-exploitation technique to acquire a complete NTDS.DIT dump, thereby obtaining comprehensive domain credentials. The attacker’s toolkit utilized various sophisticated tools, including Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, and NetExec, along with custom Rust utilities for credential collection. Although the specific objective of the campaign remains undetermined by GreyNoise, the achieved access could have been used for data theft or launching ransomware operations. System administrators are strongly advised to immediately apply the emergency security updates provided by the vendor to address CVE-2026-81578 and CVE-2026-82078 and adhere to the vendor's recommendations provided in the relevant bulletin. The analysis highlights that even with valid credentials, the efficacy of security measures diminishes sharply after initial access, emphasizing the critical need for robust preventative measures. |