Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI-Powered Attack Exploits PaperCut Vulnerabilities

AI-Powered Attack Exploits PaperCut Vulnerabilities

Posted on September 10, 2026 By CWS

A cyber attack leveraging artificial intelligence has been attributed to a Russian-speaking threat actor targeting vulnerabilities in PaperCut NG/MF software. Recent findings by Blackpoint Cyber and GreyNoise highlight the use of AI to exploit security flaws, impacting over 440 instances globally. The activity traces back to IP address ‘45.142.193[.]132’, known for unauthorized scanning and brute-force attempts.

Vulnerability Exploitation Details

The attack exploits CVE-2026-81578 and CVE-2026-82078, involving authentication bypass and remote code execution, particularly affecting educational institutions across the U.S., U.K., and several other countries. Arctic Wolf reports post-exploitation activities, including Windows registry collection and Metasploit deployments, aiming to gather sensitive configuration data.

GreyNoise has tracked the IP address since July 2026, noting its use in probing systems from various vendors like Palo Alto and Citrix. The attackers constructed a lab with vulnerable PaperCut software to develop and test their exploits, using services like Netlas.io for target list generation.

AI-Driven Attack Strategy

The attackers utilized OpenAI Codex and other AI resources to deploy hundreds of AI agents, aiming to compromise PaperCut instances in 48 countries. Despite attempts to avoid certain regions, some countries were inadvertently targeted. The campaign rapidly achieved code execution and credential harvesting, highlighting AI’s role in accelerating cyber attacks.

In under four hours, the attackers moved from an empty workspace to compromising real targets, with some organizations breached in mere seconds. The attacker’s ultimate goals remain uncertain, but potential motives include selling access or executing ransomware attacks.

Advanced Techniques and Implications

Blackpoint’s investigation reveals the attacker’s use of AI in vulnerability research and exploit development. The campaign involved iterative testing and adaptation, minimizing human effort through AI-driven automation. Python scripts facilitated task management, while open-source tools like Hindsight and AionUi supported AI operations.

This campaign underscores the growing role of AI in cybercrime, reducing manual labor and enhancing attack efficiency. The use of AI in such efforts poses significant challenges for cybersecurity defenses, necessitating advanced strategies to mitigate these evolving threats.

The integration of AI into attack workflows not only aids in malware development but also in managing operational complexities. As cyber threats evolve, understanding and countering AI-assisted attacks becomes crucial for safeguarding digital infrastructures.

The Hacker News Tags:AI agents, AI attack, CVE-2026, cyber attack, cyber defense, cyber threat, Cybersecurity, data breach, Hackers, network security, OpenAI Codex, PaperCut vulnerability, remote code execution, security flaw, threat analysis

Post navigation

Previous Post: OpenMatter Restructures Leadership to Boost Global Growth
Next Post: Amazon Strengthens Board with Cybersecurity Expert

Related Posts

Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave The Hacker News
30,000 Facebook Accounts Hacked in Phishing Scam 30,000 Facebook Accounts Hacked in Phishing Scam The Hacker News
E.U. Demands Expanded Access for Rival AI on Android E.U. Demands Expanded Access for Rival AI on Android The Hacker News
Google Integrates Rust DNS Parser in Pixel 10 for Security Google Integrates Rust DNS Parser in Pixel 10 for Security The Hacker News
 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections $50 Battering RAM Attack Breaks Intel and AMD Cloud Security Protections The Hacker News
The State of Cybersecurity in 2025: Key Segments, Insights, and Innovations  The State of Cybersecurity in 2025: Key Segments, Insights, and Innovations  The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark