PaperCut Vulnerabilities Exploited via AI Attacks
GreyNoise has reported that two recently disclosed vulnerabilities in PaperCut NG/MF have been leveraged in AI-driven attacks affecting hundreds of organizations globally.
Key Vulnerabilities
The flaws, tracked as CVE-2026-82078 and CVE-2026-81578, were revealed on August 27 as zero-day exploits and addressed the following day. These vulnerabilities enable remote unauthenticated attackers to circumvent authentication mechanisms and execute arbitrary code on unpatched PaperCut NG/MF systems.
CVE-2026-82078
Details about this vulnerability were not explicitly provided in the report, but it is part of the exploits used in the AI-powered attacks.
CVE-2026-81578
This vulnerability was also exploited to bypass authentication and execute arbitrary code on affected systems.
Attack Activity and AI Integration
Several days after the disclosures, WatchTowr threat intelligence lead Jake Knott noted a surge in activity surrounding the vulnerabilities. Knott speculated that initial access brokers were likely involved in the exploitation efforts. This week, GreyNoise disclosed that a Russian-speaking threat actor utilized artificial intelligence to develop, test, and deploy exploits against 440 PaperCut NG/MF deployments.
Targeted Organizations and Impact
The actor targeted 395 organizations across 48 countries, aiming to achieve remote code execution (RCE) and credential theft. GreyNoise highlighted that the adversary explicitly attempted to avoid targeting entities in 28 specific countries, but this restraint was not fully effective in all cases.
Attack Vectors
The threat intelligence firm outlined three primary attack vectors used during the campaign:
- Extracting LSASS process memory and registry secrets from domain-joined hosts
- Executing NoPac attacks against unpatched systems
- Adding a new account to the Domain Admins group if the host functioned as a Domain Controller
Results of the Campaign
According to GreyNoise, the attackers harvested credentials from 280 compromised hosts, exfiltrated secrets from 137 of them, and gained domain admin privileges in 12 instances. Of the 440 affected deployments, 204 belonged to entities in the education sector. Additional organizations in retail/professional services, real estate/hospitality, IT/MSP, non-profit/charity, library, and manufacturing/utilities sectors were also impacted.
Implications and Recommendations
The report underscores the evolving tactics of threat actors, who are increasingly leveraging AI to automate and scale exploitation efforts. GreyNoise emphasized that it remains unclear whether the actor is focusing solely on initial access for resale or plans to pursue follow-on objectives such as data exfiltration or ransomware deployment. The incident highlights the critical importance of timely patching and robust monitoring for systems running PaperCut NG/MF. Organizations are urged to verify their deployments against the disclosed vulnerabilities and implement additional safeguards to mitigate risks associated with AI-enhanced attack methodologies.
According to GreyNoise, the integration of AI in the campaign allowed the threat actor to compromise systems within minutes or even seconds. However, success rates varied, with domain administrator access achieved in only 12 victim organizations.
