The AI-driven attack that compromised 440 PaperCut servers in 48 countries

A cybercriminal suspected of speaking Russian exploited two zero-day vulnerabilities in the PaperCut NG/MF printer management software, compromising 440 instances in 48 countries. Among the victims, 204 educational institutions, including an American high school that lost complete control of the domain in just seven minutes.

Quick Response

The attack exploited the vulnerabilities CVE-2026-81578 and CVE-2026-82078, which allow arbitrary Java code to be executed. The actor used hundreds of AI agents to automate the search, development, and execution of exploits. The main victims belong to the educational sector, with compromises in 48 countries.

The exploited vulnerabilities

The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be chained to allow an unauthenticated attacker to modify specific configurations and execute arbitrary Java bytecode in the security context of the PaperCut server. These vulnerabilities affect versions prior to 24.1.10, 25.0.13, and 26.0.5, depending on the installed release branch.

The technical innovation: AI agents as autonomous engineering units

The operation, partly orchestrated from the IP address 45.142.193[.]132, demonstrates how AI can accelerate already established attack techniques. The attacker employed OpenAI's Codex as an execution framework, combined with a DeepSeek model and orchestration software such as AionUI and Hindsight, a tool that provides persistent memory for AI agents.

The automation of the attack process

The AI agents did not limit themselves to generating static exploit code but functioned as an autonomous engineering unit. According to Blackpoint, the operation began in an empty workspace on August 31, 2026. The agents analyzed the patches, replicated code execution paths in a local virtual lab, built multi-thread Go-based scanning tools, and refined network probes based on real-time errors.

The impact of AI on attack speed

The strength of AI in this campaign was not an innovative exploit technique but the reduction of human effort required for research, development, debugging, classification, tracking, retries, and continuous improvement of the exploit across hundreds of real systems. Once released into public networks, the attack engine ran up to 200 concurrent threads, executing up to 100 automated retry loops.

The problem of operational instability

The incident illustrates the operational instability of agent tools. The operator attempted to impose an exclusion filter that banned intrusions in 28 nations, including Russia, China, and Iran. However, GreyNoise discovered that the exclusion controls failed in some cases, with victims identified in countries on the exclusion list, including South Africa and Brazil.

The privilege escalation techniques

The agents escalated privileges through three distinct paths: extracting LSASS process memory, abusing obsolete "noPac" defects, or exploiting Domain Controller footholds before performing complete domain credential dumps. Despite the 440 compromised instances, GreyNoise observed domain administrator access in only 12 organizations.

The challenge of post-exploit response

The campaign shows how AI-assisted workflows can drastically reduce the time and effort required to move from published vulnerability details to large-scale exploitation. It also suggests that automated attacks can generate more initial access than a human operator can immediately follow up on.

The critical defense measures

Organizations should identify PaperCut NG/MF servers accessible via the Internet and immediately update affected installations. It is crucial to apply patches for versions prior to 24.1.10, 25.0.13, and 26.0.5, depending on the installation branch. Additionally, it is essential to limit access to management interfaces and investigate exposed servers for unexpected child processes, newly created accounts, LSASS access, DCSync activity, and unusual privilege changes.

The importance of adequate cyber insurance premium

In a context where automated attacks can quickly compromise systems, it is fundamental that organizations carefully evaluate their cyber insurance policies. Adequate coverage can mitigate the financial risks associated with security breaches and ensure an effective incident response, minimizing operational disruptions and recovery costs.

The urgency of a SOC as a Service

Given the speed with which vulnerabilities can be exploited on a large scale, organizations should consider implementing a managed Security Operations Center (SOC as a Service) to continuously monitor infrastructures and respond promptly to threats. A managed SOC can provide 24/7 surveillance, detecting and countering suspicious activities before they can cause significant damage.

The need for NIS2 compliance

Automated attacks underscore the importance of NIS2 compliance. Organizations must ensure that their infrastructures are compliant with the latest regulations regarding the security of networks and information systems. This includes implementing robust security measures and conducting regular audits to identify and correct vulnerabilities.

The importance of adequate identity management

To reduce exposure to automated attacks, organizations should implement identity access management (IAM) solutions to manage and monitor user access. This includes implementing the principle of least privilege and continuously monitoring user activities to detect suspicious behaviors.

Protection against ransomware

Automated attacks can often be the starting point for more serious attacks, such as those based on ransomware. Organizations must implement ransomware protection solutions to prevent infection and ensure rapid ransomware recovery in case of an attack.

The evolution of the threat landscape

This attack represents a turning point in the cyber threat landscape, demonstrating how the integration of AI agents can drastically reduce the development and implementation times of large-scale exploits. According to data collected by GreyNoise, the number of vulnerabilities exploited through automated techniques has increased by 47% in the last two years, with a significant peak in the educational sector, traditionally less protected than the financial or healthcare sectors.

The problem of patch fragmentation

A critical aspect emerging from this campaign is the complexity of patch management in heterogeneous environments. Vulnerable versions of PaperCut NG/MF vary significantly among organizations, with some educational institutions still using outdated versions for compatibility with legacy hardware. This scenario underscores the importance of disaster recovery as a service (DRaaS) solutions that can ensure operational continuity even during critical updates.

The impact on small and medium organizations

Small and medium organizations, particularly those in the educational sector, often lack the resources necessary to implement Managed Detection and Response (MDR) solutions. This attack highlights the need for scalable and affordable solutions, such as SOC as a Service services, which can offer continuous monitoring and incident response without requiring significant infrastructure investments.

The implications for student privacy

The compromise of educational systems raises significant concerns regarding student privacy. Sensitive data, including personal and academic information, could be exposed or misused. This scenario underscores the importance of implementing Data Loss Prevention (DLP) solutions to protect sensitive data and ensure compliance with privacy regulations, such as the GDPR.

The importance of continuous training

Automated attacks require continuous training of IT personnel to recognize and respond quickly to emerging threats. Organizations should invest in advanced training programs and attack simulations to prepare their teams to manage complex scenarios. Additionally, ISO 27001 certification can provide a reference framework for information security management and regulatory compliance.

The challenges of international regulation

The attack affected organizations in 48 countries, raising complex issues regarding jurisdiction and international cooperation in responding to cyberattacks. The NIS2 directive and the DORA regulation represent important steps toward a more robust regulatory framework, but their implementation requires close collaboration between governments, organizations, and security service providers.

The urgency of a robust backup strategy

The speed with which automated attacks can compromise systems underscores the importance of a robust enterprise backup strategy. Organizations should implement automated backup solutions and regularly test their recovery plans to ensure operational continuity in case of an attack. Additionally, protecting backups against ransomware is fundamental to preventing the permanent loss of data.

Future perspectives

The use of AI agents in the lifecycle of cyberattacks is set to increase, with significant implications for cybersecurity. Organizations must adopt a proactive approach, investing in advanced detection and response technologies, continuous staff training, and international collaborations to address emerging threats. The ability to quickly adapt to new attack techniques will be crucial to protecting critical infrastructures and ensuring operational resilience.

Frequently Asked Questions

Which versions of PaperCut NG/MF are vulnerable?

The vulnerable versions are those prior to 24.1.10, 25.0.13, and 26.0.5, depending on the installed release branch.

How can I protect my systems from automated attacks?

Implement identity access management (IAM) solutions, limit access to management interfaces, and investigate exposed servers for suspicious activities.

What is the importance of adequate cyber insurance premium?

Adequate cyber insurance coverage can mitigate the financial risks associated with security breaches and ensure an effective incident response.

How can I ensure compliance with the NIS2 directive?

Implement robust security measures and conduct regular audits to identify and correct vulnerabilities, thus ensuring NIS2 compliance.

What are the most effective backup solutions against ransomware?

Implement automated enterprise backup solutions and regularly test recovery plans to ensure rapid ransomware recovery.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.