Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI-Powered Cyberattack Exploits PaperCut Vulnerabilities

AI-Powered Cyberattack Exploits PaperCut Vulnerabilities

Posted on September 9, 2026 By CWS

A significant cyberattack orchestrated by a Russian-speaking hacker group has leveraged artificial intelligence on an extensive scale. Utilizing numerous autonomous AI agents, the group targeted critical weaknesses in the PaperCut NG/MF print management software. This resulted in the compromise of 440 servers across 395 organizations situated in 48 countries.

Global Detection and Attack Methods

Security specialists at GreyNoise detected this campaign through their Global Observation Grid, a sophisticated network of sensors that identifies live attack activities on monitored infrastructure. The attackers operated from IP address 45.142.193.132, a source flagged by GreyNoise since early July 2026 for probing internet-exposed systems from several vendors including Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.

On August 31, 2026, the focus shifted towards exploiting two specific PaperCut vulnerabilities: CVE-2026-81578 and CVE-2026-82078. These include an authentication bypass and an unsafe reflection remote code execution flaw, respectively.

Exploitation of PaperCut Flaws

PaperCut NG/MF, a commonly used self-hosted print management application, runs with SYSTEM-level privileges on Windows and connects directly to Active Directory, presenting a valuable target for attackers aiming for lateral movement within enterprise networks. The attacker initially created a private lab environment mimicking a vulnerable PaperCut setup to develop and test their exploits before executing them.

The threat actor compiled target lists using Netlas.io through a compromised API key. Once remote code execution and credential harvesting were verified, they deployed hundreds of AI agents powered by OpenAI’s Codex and a DeepSeek model, in conjunction with public offensive tools like Mimikatz, Certipy, Rubeus, and Impacket. The operation was swift, taking under four hours to execute code on a real target, with domain administrator access achieved two hours later.

Impact and Future Implications

The AI-driven campaign rapidly compromised 11 organizations in just 26 seconds and, in one instance, breached a U.S. high school network, achieving full domain admin access in seven minutes. Despite the scale, only 12 out of the 440 compromised instances confirmed domain administrator access, with escalation times varying from five to 144 minutes.

GreyNoise identified three main attack vectors: utilizing LSASS memory and registry secrets for pass-the-hash attacks, exploiting unpatched “noPac” vulnerabilities CVE-2021-42278 and CVE-2021-42287, and adding rogue accounts to Domain Admins when PaperCut was run on a domain controller. In successful cases, DCSync operations were used to exfiltrate the NTDS.DIT credential database.

Interestingly, the attacker’s AI agents were programmed to avoid 28 countries, including Russia, China, and Iran. However, some victims were still found in these regions, indicating possible deviations by the autonomous agents. In one instance, Cloudflare’s Web Application Firewall effectively blocked an exploitation attempt, highlighting the importance of robust security measures.

The United States was most affected, with 98 victim organizations, followed by the UK, France, and Spain. Educational institutions represented a significant portion of affected systems, likely due to PaperCut’s popularity in this sector. The ultimate intent of the attackers remains uncertain, but the potential for selling access to ransomware groups or pursing direct extortion is high. GreyNoise continues to work with incident response teams to alert affected organizations and shares indicators of compromise via their public GitHub repository.

Cyber Security News Tags:AI agents, AI security, cyber threat intelligence, Cyberattack, global cybersecurity, GreyNoise research, network exploitation, network security, PaperCut vulnerabilities, ransomware threat

Post navigation

Previous Post: Fortinet Addresses Critical Security Flaws in Key Products

Related Posts

Android 16 Comes with Advanced Device-level Security Setting Protection for 3 Billion Devices Android 16 Comes with Advanced Device-level Security Setting Protection for 3 Billion Devices Cyber Security News
GrayCharlie Targets WordPress Sites with Malicious Scripts GrayCharlie Targets WordPress Sites with Malicious Scripts Cyber Security News
FortiDDoS OS Command Injection Vulnerability Let Attackers Execute Unauthorized Commands FortiDDoS OS Command Injection Vulnerability Let Attackers Execute Unauthorized Commands Cyber Security News
Windows Defender Zero-Day Exploit Unveiled by Researcher Windows Defender Zero-Day Exploit Unveiled by Researcher Cyber Security News
BreachLock Recognized in 2026 Gartner AEV Guide BreachLock Recognized in 2026 Gartner AEV Guide Cyber Security News
Chrome 140 Released With Fix For Six Vulnerabilities that Enable Remote Code Execution Attacks Chrome 140 Released With Fix For Six Vulnerabilities that Enable Remote Code Execution Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattack Exploits PaperCut Vulnerabilities
  • Fortinet Addresses Critical Security Flaws in Key Products
  • AI User Accounts Targeted by Infostealer Logs
  • Critical Patch for Windows Remote Desktop Flaw
  • Meta Unveils AI Assistant Muse with Privacy Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattack Exploits PaperCut Vulnerabilities
  • Fortinet Addresses Critical Security Flaws in Key Products
  • AI User Accounts Targeted by Infostealer Logs
  • Critical Patch for Windows Remote Desktop Flaw
  • Meta Unveils AI Assistant Muse with Privacy Focus

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark