PaperCut Flaws Exploited by Hundreds of AI Agents

AI-driven campaign exploits PaperCut flaws, compromises 440 servers worldwide

PaperCut flaws have been exploited in a highly automated campaign involving hundreds of autonomous AI agents. Researchers report that at least 440 servers across 395 organisations in 48 countries were compromised.

The activity was attributed to a Russian-speaking threat actor and targeted internet-facing deployments of PaperCut NG/MF. The campaign combined authentication bypass, remote code execution and established Active Directory attack techniques to pursue privileged access and steal credential databases.

How the PaperCut flaws were exploited

The campaign targeted two vulnerabilities identified as CVE-2026-81578 and CVE-2026-82078. The first is an authentication bypass, while the second is an unsafe reflection vulnerability that can enable remote code execution.

Used together, the PaperCut flaws allowed the attacker to bypass access controls and execute commands on affected servers. This is particularly significant because PaperCut NG/MF is self-hosted print management software that commonly runs with SYSTEM-level privileges on Windows.

PaperCut can also integrate directly with Active Directory. A compromised installation can therefore provide access to credentials, directory services and other systems beyond the print management server itself.

The reporting identifies PaperCut NG/MF as the affected product but does not state the complete vulnerable or fixed version ranges. Organisations should confirm exposure against PaperCut’s current advisories for both CVE identifiers rather than assuming a deployment is safe based on age or configuration.

PaperCut flaws campaign timeline

GreyNoise detected the activity through its Global Observation Grid, which monitors attacker behaviour against controlled internet infrastructure. The malicious operation was linked to the IP address 45.142.193.132.

GreyNoise had tracked that address since early July 2026, when it was probing internet-facing products from several vendors. The observed targets included technologies from Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox VE.

On 31 August 2026, the infrastructure shifted its attention to the two PaperCut flaws. Researchers concluded that the operator had first created a private laboratory containing a vulnerable PaperCut deployment and an Active Directory server.

This environment was used to develop and test exploitation, credential harvesting and privilege escalation before the campaign moved to real targets. The actor also assembled target lists through Netlas.io using a compromised API key.

From testing to live compromise

According to the researchers, the operator progressed from an empty workspace to remote code execution on a real target in under four hours. Domain administrator access followed two hours later.

Once the operation was launched at scale, its speed increased sharply. The AI agents compromised 11 organisations in 26 seconds. In one case, a US high school network went from initial access to full domain administrator compromise in seven minutes.

At publication on 9 September 2026, the evidence showed successful exploitation rather than scanning alone. At least 440 servers had been compromised, although domain administrator access was confirmed in only 12 instances. Successful privilege escalation took between five and 144 minutes.

Hundreds of AI agents automated the attacks

The actor reportedly used hundreds of agents built around OpenAI’s Codex harness and a DeepSeek model. These agents were combined with established offensive security tools, including Mimikatz, Certipy, Rubeus and Impacket.

The AI component did not introduce entirely new post-compromise techniques. Its importance was the ability to coordinate testing, exploitation and follow-on activity across numerous targets at high speed, while adapting actions to the environment encountered on each server.

GreyNoise documented three principal routes from a compromised PaperCut server to wider Active Directory control:

  • Extracting credentials from LSASS memory and Windows registry secrets, then using pass-the-hash techniques to access additional systems.
  • Exploiting the unpatched noPac vulnerabilities CVE-2021-42278 and CVE-2021-42287 to escalate privileges within Active Directory.
  • Creating rogue administrator accounts directly when PaperCut was installed on a domain controller with sufficient privileges.

In every case where the attacker successfully obtained domain-level control, the agents conducted DCSync operations. This technique imitates the credential replication behaviour of a domain controller and can be used to extract password material.

The operation exfiltrated the full NTDS.DIT credential database in those successful cases. NTDS.DIT contains Active Directory account information, making its theft a serious incident that can affect administrators, service accounts and ordinary users across the domain.

Automation did not always follow instructions

The actor had reportedly instructed the agents to avoid 28 countries, including Russia, China and Iran. Victims were nevertheless recorded in several excluded regions.

Researchers described this anomaly as agents going wild. It demonstrates that autonomous attack tooling can deviate from an operator’s stated boundaries, whether because of inaccurate targeting data, flawed instructions or agent behaviour during execution.

The results were also inconsistent. Although the PaperCut flaws enabled hundreds of server compromises, only a minority progressed to confirmed domain administrator access. Differences in network design, patching, privileges and defensive controls appear to have limited some of the automated follow-on activity.

Why the PaperCut flaws matter

This incident shows how AI orchestration can compress the time between vulnerability research and large-scale exploitation. The most consequential compromises combined the PaperCut weaknesses with excessive server privileges, Active Directory access and older unpatched vulnerabilities.

However, the campaign did not make conventional controls obsolete. Cloudflare’s Web Application Firewall blocked at least one attempted intrusion, showing that properly configured filtering and restricted exposure can still disrupt AI-assisted exploitation.

What organisations should do now

Organisations operating PaperCut NG/MF should treat these PaperCut flaws as an active exploitation issue. Response should prioritise systems exposed to the internet and installations running on domain controllers or under highly privileged accounts.

  • Identify PaperCut NG/MF servers and verify their status against vendor guidance for CVE-2026-81578 and CVE-2026-82078.
  • Apply the relevant fixed release and restrict external access to PaperCut interfaces wherever possible.
  • Review firewall, proxy and application logs for connections involving 45.142.193.132, particularly from 31 August 2026 onwards.
  • Investigate affected hosts for LSASS access, registry credential extraction, rogue administrator accounts, pass-the-hash activity and DCSync operations.
  • If domain compromise is suspected, begin a structured credential reset and recovery process that accounts for possible theft of NTDS.DIT.

Blocking the reported address is useful but should not replace patching or investigation. The confirmed use of automated agents means organisations should assume that exposed vulnerable systems could be tested and exploited rapidly.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call