AI Agents Accelerate Exploitation of PaperCut Vulnerabilities
Share
A suspected Russian-speaking cyber actor has utilised hundreds of artificial intelligence (AI) agents to automate the exploitation of security flaws in PaperCut NG/MF software, compromising more than 440 instances globally.
Research from threat intelligence firms Blackpoint Cyber and GreyNoise reveals that the attacker used AI to manage the entire lifecycle of the campaign, from vulnerability research to large-scale execution. The activity has impacted at least 395 organisations across 48 countries, with a significant focus on the education sector in nations including the United States, the United Kingdom, Canada, and Australia.
AI-Powered Exploitation Pipeline
The campaign targets a combination of two vulnerabilities: CVE-2026-81578, an authentication bypass, and CVE-2026-82078, which allows for remote code execution (RCE).
The adversary’s workflow integrated AI models, including OpenAI Codex and a DeepSeek model, to assist in exploit development and target filtering. Unlike traditional manual attacks, the threat actor employed an iterative process where AI helped research, debug, and refine exploits through a persistent feedback loop.
GreyNoise reported that the efficiency of the AI-driven approach allowed for unprecedented speed. Once the campaign reached full scale, the attacker compromised at least 11 organisations in just 26 seconds. In one instance involving a high school in the United States, the attacker progressed from initial access to full domain administrator access in only seven minutes.
Operational Complexity and Tools
The infrastructure used by the actor included specialised tools to support the AI agents. These included Hindsight, which provided a persistent memory service for the agents, and AionUi, a unified graphical workspace for running multiple agents concurrently.
The attacker also utilised a wide array of established offensive security tools, such as Mimikatz, SharpHound, and Impacket, to facilitate post-exploitation activities. Blackpoint Cyber noted that the AI was used not just for code generation, but to troubleshoot failures, manage target lists, and adapt the attack framework to different operating systems and environments.
The attacker’s end goal remains unconfirmed. While the actor successfully gained domain administrator access in 12 organisations, it is unclear whether the primary objective is to develop access for other groups or to directly conduct data theft or ransomware deployment.
Organisations using PaperCut NG/MF should ensure their systems are updated with the latest security patches to mitigate the risk of these exploits.




Leave a Reply