Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI-Powered Attack Exploits PaperCut Vulnerabilities

AI-Powered Attack Exploits PaperCut Vulnerabilities

Posted on September 10, 2026 By CWS

A cyber attack leveraging artificial intelligence has been attributed to a Russian-speaking threat actor targeting vulnerabilities in PaperCut NG/MF software. Recent findings by Blackpoint Cyber and GreyNoise highlight the use of AI to exploit security flaws, impacting over 440 instances globally. The activity traces back to IP address ‘45.142.193[.]132’, known for unauthorized scanning and brute-force attempts.

Vulnerability Exploitation Details

The attack exploits CVE-2026-81578 and CVE-2026-82078, involving authentication bypass and remote code execution, particularly affecting educational institutions across the U.S., U.K., and several other countries. Arctic Wolf reports post-exploitation activities, including Windows registry collection and Metasploit deployments, aiming to gather sensitive configuration data.

GreyNoise has tracked the IP address since July 2026, noting its use in probing systems from various vendors like Palo Alto and Citrix. The attackers constructed a lab with vulnerable PaperCut software to develop and test their exploits, using services like Netlas.io for target list generation.

AI-Driven Attack Strategy

The attackers utilized OpenAI Codex and other AI resources to deploy hundreds of AI agents, aiming to compromise PaperCut instances in 48 countries. Despite attempts to avoid certain regions, some countries were inadvertently targeted. The campaign rapidly achieved code execution and credential harvesting, highlighting AI’s role in accelerating cyber attacks.

In under four hours, the attackers moved from an empty workspace to compromising real targets, with some organizations breached in mere seconds. The attacker’s ultimate goals remain uncertain, but potential motives include selling access or executing ransomware attacks.

Advanced Techniques and Implications

Blackpoint’s investigation reveals the attacker’s use of AI in vulnerability research and exploit development. The campaign involved iterative testing and adaptation, minimizing human effort through AI-driven automation. Python scripts facilitated task management, while open-source tools like Hindsight and AionUi supported AI operations.

This campaign underscores the growing role of AI in cybercrime, reducing manual labor and enhancing attack efficiency. The use of AI in such efforts poses significant challenges for cybersecurity defenses, necessitating advanced strategies to mitigate these evolving threats.

The integration of AI into attack workflows not only aids in malware development but also in managing operational complexities. As cyber threats evolve, understanding and countering AI-assisted attacks becomes crucial for safeguarding digital infrastructures.

The Hacker News Tags:AI agents, AI attack, CVE-2026, cyber attack, cyber defense, cyber threat, Cybersecurity, data breach, Hackers, network security, OpenAI Codex, PaperCut vulnerability, remote code execution, security flaw, threat analysis

Post navigation

Previous Post: OpenMatter Restructures Leadership to Boost Global Growth
Next Post: Amazon Strengthens Board with Cybersecurity Expert

Related Posts

Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU Qualcomm Fixes 3 Zero-Days Used in Targeted Android Attacks via Adreno GPU The Hacker News
INC Ransomware Dominates 2026 with Over 830 Attacks INC Ransomware Dominates 2026 with Over 830 Attacks The Hacker News
AI-Powered Threats Demand New Boardroom Strategies AI-Powered Threats Demand New Boardroom Strategies The Hacker News
Exploitation of TrueConf Flaw Targets Southeast Asian Governments Exploitation of TrueConf Flaw Targets Southeast Asian Governments The Hacker News
ClickFix Campaigns Enhance Malware Tactics with New Loaders ClickFix Campaigns Enhance Malware Tactics with New Loaders The Hacker News
Cloud Tenants Could Threaten Power Grids Without Exploits Cloud Tenants Could Threaten Power Grids Without Exploits The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark