Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI-Driven Exploits Target PaperCut Vulnerabilities

AI-Driven Exploits Target PaperCut Vulnerabilities

Posted on September 11, 2026 By CWS

Recent vulnerabilities within PaperCut NG/MF software have become the focus of AI-driven cyberattacks impacting numerous organizations globally, according to a report from GreyNoise.

Details of the Exploited Vulnerabilities

Identified as CVE-2026-82078 and CVE-2026-81578, these security flaws were initially disclosed as zero-day vulnerabilities on August 27. They were promptly addressed with patches the following day. The flaws allow remote, unauthenticated attackers to circumvent authentication protocols and execute arbitrary code on affected PaperCut NG/MF systems.

In subsequent days, Jake Knott, head of threat intelligence at WatchTowr, highlighted the growing activity surrounding these vulnerabilities, suggesting that initial access brokers might be exploiting them.

AI Utilization in Cyberattacks

This week, GreyNoise reported that a Russian-speaking threat actor had utilized artificial intelligence to develop, test, and deploy exploits against 440 PaperCut NG/MF installations. The assailant targeted vulnerable systems in 395 organizations across 48 nations for remote code execution and credential theft.

While the attacker avoided entities in 28 countries, GreyNoise noted that the effort to limit targets was not entirely successful. The AI-driven approach enabled rapid compromise of some systems, achieving domain admin access in 12 cases.

Impact and Observations

Three attack pathways were identified in the campaign, including harvesting memory and registry secrets from domain member hosts, exploiting unpatched instances via NoPac attacks, and adding new accounts to Domain Admins on Domain Controllers. Credential harvesting was performed on 280 compromised hosts, with secrets exfiltrated from 137, and domain admin privileges secured in 12 instances.

Of the 440 affected deployments, 204 were part of the education sector. Other impacted sectors included retail/professional services, real estate/hospitality, IT/MSP, non-profit/charity, libraries, and manufacturing/utilities.

GreyNoise questions whether this threat actor is solely focused on developing access to transfer to others or intends to directly exploit the access for further objectives, such as data theft or ransomware deployment.

Future Outlook

As cybersecurity threats evolve, organizations need to remain vigilant and proactive in applying security patches to mitigate risks. The incidents underscore the importance of robust defense mechanisms against AI-enhanced attacks. Continuous monitoring and threat intelligence sharing are essential to safeguarding against such sophisticated cyber threats in the future.

Security Week News Tags:AI attacks, credential harvesting, Cybersecurity, GreyNoise, PaperCut, remote code execution, security patches, threat intelligence, Vulnerabilities, zero-day exploits

Post navigation

Previous Post: AI Exploited in Cyber Attacks Across the Globe
Next Post: GuardBreaker Threatens AI Malware Analysis Security

Related Posts

Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit Google Sues Chinese Cybercriminals Behind ‘Lighthouse’ Phishing Kit Security Week News
PromptLock Only PoC, but AI-Powered Ransomware Is Real PromptLock Only PoC, but AI-Powered Ransomware Is Real Security Week News
Steelmaker Nucor Says Hackers Stole Data in Recent Attack Steelmaker Nucor Says Hackers Stole Data in Recent Attack Security Week News
Sensitive Information Stolen in Sensata Ransomware Attack Sensitive Information Stolen in Sensata Ransomware Attack Security Week News
N-able Releases Patch for Exploited N-central Vulnerability N-able Releases Patch for Exploited N-central Vulnerability Security Week News
Cyber Insurance Enhances CISO Budget Negotiations Cyber Insurance Enhances CISO Budget Negotiations Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • KATARU IoT Malware: Linux Exploits and DDoS Tactics
  • GitLab Patch Targeted by Attackers Within 24 Hours
  • Russian Hackers Exploit AI to Revamp Undetected Malware
  • GuardBreaker Threatens AI Malware Analysis Security
  • AI-Driven Exploits Target PaperCut Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • KATARU IoT Malware: Linux Exploits and DDoS Tactics
  • GitLab Patch Targeted by Attackers Within 24 Hours
  • Russian Hackers Exploit AI to Revamp Undetected Malware
  • GuardBreaker Threatens AI Malware Analysis Security
  • AI-Driven Exploits Target PaperCut Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark