Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » PaperCut AI Exploitation Campaign Breached 395 Organisations Across 48 Countries
    Technology

    PaperCut AI Exploitation Campaign Breached 395 Organisations Across 48 Countries

    Gary BehanBy Gary Behan18/09/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    PaperCut AI exploitation campaign
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    A PaperCut AI exploitation campaign linked to a likely Russian-speaking threat actor has compromised at least 440 PaperCut NG/MF instances across 395 distinct organisations in 48 countries, according to attack and threat intelligence company GreyNoise. The operation used hundreds of AI agents to build, test, and refine exploits, and managed to compromise at least 11 organisations in 26 seconds once it reached full operational tempo.

    The two vulnerabilities at the heart of the attack, CVE-2026-81578 and CVE-2026-82078, both affect PaperCut Software and had been flagged as actively exploited earlier in September 2026. According to Arctic Wolf, multiple security firms detected initial exploitation as early as 26 August 2026, and PaperCut issued Emergency Patch Release 3 on 1 September 2026 in response. The severity of the pair is not equal: CVE-2026-81578 carries a CVSS score of 8.8 (High), while CVE-2026-82078 scores 9.4 (Critical).

    How the PaperCut AI Exploitation Campaign Was Built

    GreyNoise says the campaign began on 31 August, combining OpenAI’s Codex and DeepSeek models with commodity offensive tools. The AI agents were responsible for building and refining exploits, but also for generating target lists via the Netlas internet scanning and discovery platform, effectively automating reconnaissance alongside the attack itself.

    The speed was the headline detail. GreyNoise noted that ‘the adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organisations in 26 seconds.’ In one case, ‘the adversary went from initial access to full domain administrator in seven minutes against a high school in the United States.’

    The threat actor specified a list of countries to avoid, Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa among them. The agents did not consistently follow those rules, GreyNoise noted.

    Credential Harvesting, Attack Paths and a Full Toolkit

    Of the 395 organisations affected, attackers harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and gained administrator privileges at 12. The education sector bore roughly half of all breaches. The United States was the most targeted country, followed by the United Kingdom, France, Spain, and Canada.

    GreyNoise observed three distinct attack paths after initial PaperCut compromise. The first involved dumping LSASS memory and registry secrets from domain-joined servers, then using recovered credential hashes against domain controllers in a pass-the-hash attack. The second exploited environments still vulnerable to CVE-2021-42278 and CVE-2021-42287 via the noPac technique. The third simply added a newly created account directly to Domain Admins where PaperCut ran on a domain controller or under a domain administrator service account.

    In all three paths, the attackers used the DCSync post-exploitation technique to pull a complete NTDS.DIT dump containing domain credentials. The toolkit identified by GreyNoise includes Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust credential-collection utilities.

    GreyNoise was unable to determine the campaign’s ultimate objective, though the level of access obtained would support either data theft or ransomware operations.

    What Defenders Need to Do Now

    The PaperCut AI exploitation campaign illustrates a point GreyNoise is keen to stress: AI allows attackers to compress timelines that defenders have historically relied upon. ‘AI enables attackers to launch rapid attacks that leave defenders with very tight response margins,’ the company said. When the gap between vulnerability disclosure and working exploit can now be measured in hours, patch velocity matters more than ever.

    System administrators running PaperCut NG or MF are advised to apply the emergency security updates addressing CVE-2026-81578 and CVE-2026-82078 immediately and to follow PaperCut’s official vendor bulletin. Arctic Wolf’s advisory confirms Emergency Patch Release 3 was available from 1 September 2026, any organisation that has not yet applied it is running on borrowed time.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleKB5124008 patches Windows 11 mouse settings reset caused by August update
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    KB5124008 patches Windows 11 mouse settings reset caused by August update

    17/09/2026

    WatchGuard Firebox Ransomware Attacks Confirmed as CISA Updates KEV Catalogue

    17/09/2026

    CVE-2026-20079 Actively Exploited, CISA Orders Federal Patch by September

    17/09/2026

    CISA Advisory AA26-251A: Chinese AI Distillation Attacks Drained Billions of Tokens from US Models

    16/09/2026

    Veradigm Patient Data Breach Tied to Vendor API Credentials Stolen by Ransomware Gang

    16/09/2026

    Plex Media Server unpatched flaws leave 36,000 servers exposed online

    16/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.