A sophisticated Russian-speaking threat actor has utilized artificial intelligence to automate the exploitation of critical PaperCut NG/MF vulnerabilities, compromising hundreds of organizations across 48 countries.
- AI was used to build, test, and deploy exploits in seconds, drastically increasing attack speed.
- 440 PaperCut deployments across 395 organizations in 48 countries were targeted.
- The education sector was hardest hit, with 204 compromised deployments.
In a alarming escalation of AI-driven cyber warfare, security researchers at GreyNoise have revealed that a Russian-speaking threat actor has successfully weaponized artificial intelligence to target vulnerabilities in PaperCut NG/MF print management software. The campaign specifically exploited two critical vulnerabilities, tracked as CVE-2026-82078 and CVE-2026-81578, which were initially disclosed as zero-days on August 27.
These security flaws allowed remote, unauthenticated attackers to bypass authentication mechanisms and execute arbitrary code on vulnerable instances. While patches were released promptly, the window of opportunity was exploited with surgical precision. The integration of AI allowed the adversary to orchestrate the campaign with unprecedented efficiency, reducing the time to compromise some environments to mere seconds.
Why This Matters
BozokMedia analysis shows that this incident marks a pivotal shift in the threat landscape. We are no longer dealing with manual exploitation; AI is now being used as a force multiplier for Initial Access Brokers (IABs). By automating the 'build-test-deploy' cycle, attackers can scan and breach thousands of targets before human security teams can even trigger an alert. This democratizes high-level exploitation capabilities, making sophisticated RCE attacks common.
The shift toward AI-orchestrated exploitation means the window between vulnerability disclosure and mass compromise has shrunk from days to seconds.
The scale of the attack was vast, hitting 395 organizations in 48 different countries. Interestingly, the threat actor attempted to avoid certain jurisdictions, though these restraints failed in several instances. The primary objectives appeared to be remote code execution (RCE) and credential harvesting, with the attacker targeting 280 hosts for credentials and exfiltrating secrets from 137 of them.
The attack paths were diverse: the actor harvested LSASS process memory, mounted NoPac attacks on unpatched systems, and in high-value cases, added new accounts to Domain Admins when the target host was a Domain Controller. Despite the breadth of the attack, only 12 organizations saw their entire domains compromised.
| Metric | Impact Detail |
|---|---|
| Total Deployments Hit | 440 |
| Organizations Targeted | 395 |
| Countries Affected | 48 |
| Education Sector Hits | 204 |
| Domain Admin Access | 12 |
Beyond education, the attack spanned retail, professional services, real estate, hospitality, and manufacturing sectors. Security experts remain uncertain whether the goal was simply to sell access to other cybercriminals or to prepare the ground for massive ransomware deployments.
Frequently Asked Questions
What are the specific CVEs associated with this attack?
The attacks exploited CVE-2026-82078 and CVE-2026-81578, both of which allowed for authentication bypass and remote code execution.
How can organizations protect themselves?
Organizations should immediately update their PaperCut NG/MF instances to the latest patched versions and monitor for unauthorized account creation in Domain Admins.