Skip to content
Tech News
← Back to articles

AI-powered attack exploited PaperCut flaws to hack 395 organizations

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

This is one of the clearest documented cases of AI agents being used end-to-end in a real-world exploitation campaign, from writing and refining exploits to building target lists and executing intrusions at machine speed. The compression of attack timelines — under four hours from empty workspace to remote code execution, and seven minutes from access to domain admin — means patch windows and human-paced incident response are no longer adequate. Schools and other under-resourced IT operations, which made up roughly half of victims, are the most exposed.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — When attackers are harvesting admin credentials at scale, a hardware security key is one of the few things that stops stolen passwords from becoming a full breach. The YubiKey 5 NFC plugs into USB-A or taps via NFC to add phishing-resistant two-factor authentication to admin accounts, email, and cloud consoles. It's a simple, durable addition to any IT admin's keychain.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.

The agents were tasked with building, testing, and refining exploits for CVE-2026-81578 and CVE-2026-82078, both security flaws affecting PaperCut Software and flagged as actively exploited earlier this month.

Attack and threat intelligence company GreyNoise says the campaign began on August 31, combining OpenAI’s Codex and DeepSeek models with commodity offensive tools.

The AI agents also generated target lists through the Netlas internet scanning and discovery platform.

GreyNoise data indicates that the operation compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries.

The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and obtained administrator privileges at 12 organizations.

Most of the victims were in the education sector, accounting for roughly half of all breaches. The United States was the most targeted country, followed by the United Kingdom, France, Spain, and Canada.

According to GreyNoise, the threat actor specified a list of countries to avoid, including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa. However, the agents did not consistently follow these rules.

GreyNoise underlines that AI enables attackers to launch rapid attacks that leave defenders with very tight response margins.

“The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,” GreyNoise notes.

... continue reading