Recent vulnerabilities within PaperCut NG/MF software have become the focus of AI-driven cyberattacks impacting numerous organizations globally, according to a report from GreyNoise.
Details of the Exploited Vulnerabilities
Identified as CVE-2026-82078 and CVE-2026-81578, these security flaws were initially disclosed as zero-day vulnerabilities on August 27. They were promptly addressed with patches the following day. The flaws allow remote, unauthenticated attackers to circumvent authentication protocols and execute arbitrary code on affected PaperCut NG/MF systems.
In subsequent days, Jake Knott, head of threat intelligence at WatchTowr, highlighted the growing activity surrounding these vulnerabilities, suggesting that initial access brokers might be exploiting them.
AI Utilization in Cyberattacks
This week, GreyNoise reported that a Russian-speaking threat actor had utilized artificial intelligence to develop, test, and deploy exploits against 440 PaperCut NG/MF installations. The assailant targeted vulnerable systems in 395 organizations across 48 nations for remote code execution and credential theft.
While the attacker avoided entities in 28 countries, GreyNoise noted that the effort to limit targets was not entirely successful. The AI-driven approach enabled rapid compromise of some systems, achieving domain admin access in 12 cases.
Impact and Observations
Three attack pathways were identified in the campaign, including harvesting memory and registry secrets from domain member hosts, exploiting unpatched instances via NoPac attacks, and adding new accounts to Domain Admins on Domain Controllers. Credential harvesting was performed on 280 compromised hosts, with secrets exfiltrated from 137, and domain admin privileges secured in 12 instances.
Of the 440 affected deployments, 204 were part of the education sector. Other impacted sectors included retail/professional services, real estate/hospitality, IT/MSP, non-profit/charity, libraries, and manufacturing/utilities.
GreyNoise questions whether this threat actor is solely focused on developing access to transfer to others or intends to directly exploit the access for further objectives, such as data theft or ransomware deployment.
Future Outlook
As cybersecurity threats evolve, organizations need to remain vigilant and proactive in applying security patches to mitigate risks. The incidents underscore the importance of robust defense mechanisms against AI-enhanced attacks. Continuous monitoring and threat intelligence sharing are essential to safeguarding against such sophisticated cyber threats in the future.
