LmCast :: Stay tuned in

AI-powered attack exploited PaperCut flaws to hack 395 organizations

Recorded: Sept. 10, 2026, 4 p.m.

Original Summarized

AI-powered attack exploited PaperCut flaws to hack 395 organizations

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

IDScan confirms breach tied to 153 million stolen driver’s licenses

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityAI-powered attack exploited PaperCut flaws to hack 395 organizations

AI-powered attack exploited PaperCut flaws to hack 395 organizations

By Bill Toulas

September 10, 2026
11:55 AM
0

A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.
The agents were tasked with building, testing, and refining exploits for CVE-2026-81578 and CVE-2026-82078, both security flaws affecting PaperCut Software and flagged as actively exploited earlier this month.
Attack and threat intelligence company GreyNoise says the campaign began on August 31, combining OpenAI’s Codex and DeepSeek models with commodity offensive tools.
The AI agents also generated target lists through the Netlas internet scanning and discovery platform.
GreyNoise data indicates that the operation compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries.
The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and obtained administrator privileges at 12 organizations.
Most of the victims were in the education sector, accounting for roughly half of all breaches. The United States was the most targeted country, followed by the United Kingdom, France, Spain, and Canada.
According to GreyNoise, the threat actor specified a list of countries to avoid, including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa. However, the agents did not consistently follow these rules.
GreyNoise underlines that AI enables attackers to launch rapid attacks that leave defenders with very tight response margins.
“The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,” GreyNoise notes.
“In one instance, the adversary went from initial access to full domain administrator in seven minutes against a high school in the United States.”

Attack timelineSource: GreyNoise
The researchers observed three attack paths after exploiting the PaperCut flaws:
Dumping LSASS memory and registry secrets from domain-joined PaperCut servers, then passing recovered credential hashes to domain controllers (“pass-the-hash” attack).
Using the “noPac” attack against environments still vulnerable to CVE-2021-42278 and CVE-2021-42287.
Directly adding a newly created account to Domain Admins when PaperCut ran on a domain controller or under a domain administrator service account.
In all cases, the attackers used the DCSync post-exploitation technique to obtain a complete NTDS.DIT dump with domain credentials.
The attacker’s toolkit includes Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust credential-collection utilities.
GreyNoise could not determine the attacker’s campaign objective, but the access could be used for data theft or ransomware operations.
System administrators are advised to apply PaperCut’s emergency security updates addressing CVE-2026-81578 and CVE-2026-82078 immediately, and follow the vendor’s recommendations in this bulletin.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
Hackers build AI frameworks for widescale credential theftCISA warns of hackers exploiting critical MLflow vulnerabilityJadePuffer ransomware used AI agent to automate entire attackUS says Chinese firms extracted billions of tokens from frontier AI modelsOpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

Actively Exploited
AI
AI Agent
Artificial Intelligence
Education
PaperCut

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

Overdue a password health-check? Audit your Active Directory for free

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

An AI-powered attack was observed exploiting flaws in PaperCut NG/MF servers, leading to the compromise of at least 395 organizations across 48 countries. A threat actor, likely Russian-speaking, utilized hundreds of AI agents to orchestrate a global exploitation campaign targeting specific security vulnerabilities, namely CVE-2026-81578 and CVE-2026-82078, both of which were known to be actively exploited. The campaign leveraged advanced models such as OpenAI’s Codex and DeepSeek, combined with commodity offensive tools and the Netlas platform for target identification.

These AI agents were responsible for developing, testing, and refining the necessary exploits. The operation commenced on August 31, integrating these tools to conduct rapid infiltration. The resulting compromise affected at least 440 PaperCut instances linked to the 395 distinct organizations. The attackers successfully harvested credentials from 280 victims, obtained operating system or domain secrets from 147 victims, and secured administrator privileges in 12 organizations. The victims were predominantly located in the education sector, with the United States being the most targeted country, followed by the United Kingdom, France, Spain, and Canada. The threat actor demonstrated an ability to execute attacks at tremendous speed, as noted by GreyNoise, achieving remote code execution against a victim in under four hours and gaining primary domain administrator access in just two hours in one instance.

The post-exploitation activity involved several sophisticated attack paths observed by researchers. These included dumping Local Security Authority Subsystem Service memory and registry secrets from domain-joined PaperCut servers to facilitate a pass-the-hash attack against domain controllers. Another method involved exploiting environments still vulnerable to earlier flaws, such as CVE-2021-42278 and CVE-2021-42287, using the noPac attack. Furthermore, attackers achieved privilege escalation by directly adding newly created accounts to the Domain Admins group when PaperCut operated within a domain environment. In all scenarios, the attackers employed the DCSync post-exploitation technique to acquire a complete NTDS.DIT dump, thereby obtaining comprehensive domain credentials.

The attacker’s toolkit utilized various sophisticated tools, including Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, and NetExec, along with custom Rust utilities for credential collection. Although the specific objective of the campaign remains undetermined by GreyNoise, the achieved access could have been used for data theft or launching ransomware operations. System administrators are strongly advised to immediately apply the emergency security updates provided by the vendor to address CVE-2026-81578 and CVE-2026-82078 and adhere to the vendor's recommendations provided in the relevant bulletin. The analysis highlights that even with valid credentials, the efficacy of security measures diminishes sharply after initial access, emphasizing the critical need for robust preventative measures.