Download Privacy Needle App

Type to search

Cybersecurity

AI Agents Accelerate Exploitation of PaperCut Vulnerabilities

Share

A suspected Russian-speaking cyber actor has utilised hundreds of artificial intelligence (AI) agents to automate the exploitation of security flaws in PaperCut NG/MF software, compromising more than 440 instances globally.

Research from threat intelligence firms Blackpoint Cyber and GreyNoise reveals that the attacker used AI to manage the entire lifecycle of the campaign, from vulnerability research to large-scale execution. The activity has impacted at least 395 organisations across 48 countries, with a significant focus on the education sector in nations including the United States, the United Kingdom, Canada, and Australia.

AI-Powered Exploitation Pipeline

The campaign targets a combination of two vulnerabilities: CVE-2026-81578, an authentication bypass, and CVE-2026-82078, which allows for remote code execution (RCE).

The adversary’s workflow integrated AI models, including OpenAI Codex and a DeepSeek model, to assist in exploit development and target filtering. Unlike traditional manual attacks, the threat actor employed an iterative process where AI helped research, debug, and refine exploits through a persistent feedback loop.

GreyNoise reported that the efficiency of the AI-driven approach allowed for unprecedented speed. Once the campaign reached full scale, the attacker compromised at least 11 organisations in just 26 seconds. In one instance involving a high school in the United States, the attacker progressed from initial access to full domain administrator access in only seven minutes.

Operational Complexity and Tools

The infrastructure used by the actor included specialised tools to support the AI agents. These included Hindsight, which provided a persistent memory service for the agents, and AionUi, a unified graphical workspace for running multiple agents concurrently.

The attacker also utilised a wide array of established offensive security tools, such as Mimikatz, SharpHound, and Impacket, to facilitate post-exploitation activities. Blackpoint Cyber noted that the AI was used not just for code generation, but to troubleshoot failures, manage target lists, and adapt the attack framework to different operating systems and environments.

The attacker’s end goal remains unconfirmed. While the actor successfully gained domain administrator access in 12 organisations, it is unclear whether the primary objective is to develop access for other groups or to directly conduct data theft or ransomware deployment.

Organisations using PaperCut NG/MF should ensure their systems are updated with the latest security patches to mitigate the risk of these exploits.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.