[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fBysrC-F-kD0srcC4ODDA2-YYTGV3mOBZN42g_ZEdamg":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"55efef69-0f1e-4994-8dcf-c33ae7e414a2","PaperCut Flaws Exploited in AI-Powered Attacks","papercut-flaws-exploited-in-ai-powered-attacks-79b446","A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide. The post PaperCut Flaws Exploited in AI-Powered Attacks appeared first on SecurityWeek.","A Russian-speaking threat actor has leveraged AI to build, test, and deploy exploits against hundreds of organizations worldwide, targeting PaperCut NG\u002FMF deployments. The attacks, exploiting two zero-day vulnerabilities (CVE-2026-82078 and CVE-2026-81578), allowed for remote code execution and credential harvesting, with a significant portion of victims in the education sector. The AI-driven approach enabled rapid compromise, with some environments breached in seconds.","Russian threat actor uses AI to exploit PaperCut flaws in global attacks.","Two recent PaperCut NG\u002FMF vulnerabilities have been exploited in AI-powered attacks that hit hundreds of organizations worldwide, GreyNoise reports. Tracked as CVE-2026-82078 and CVE-2026-81578, the security defects were disclosed on August 27 as zero-days and patched the next day. They can allow remote unauthenticated attackers to bypass authentication and execute arbitrary code on vulnerable PaperCut NG\u002FMF instances. Several days later, WatchTowr threat intelligence head Jake Knott warned that the activity around the two vulnerabilities had been intensifying. Knott believed at the time that initial access brokers were likely behind the exploitation. This week, threat intelligence firm GreyNoise revealed that a Russian-speaking threat actor has used AI to build, test, and deploy exploits against 440 PaperCut NG\u002FMF deployments. The threat actor targeted the vulnerable PaperCut instances of 395 organizations in 48 countries for remote code execution (RCE) and credential harvesting.Advertisement. Scroll to continue reading. “There are other real victims that could not be attributed to a named organization. The adversary did explicitly attempt to avoid targeting entities in 28 identified countries; however, our observed victimology shows the attempted restraint failed in some instances,” GreyNoise says. The use of AI to orchestrate the campaign allowed the threat actor to compromise some environments in minutes and even seconds. The attacker’s success was not even across all organizations, with domain admin achieved against only 12 victim organizations. “It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their access to achieve follow-on objectives such as data theft or ransomware deployment,” GreyNoise notes. The threat intelligence firm observed three attack paths across the campaign: harvested LSASS process memory and registry secrets from hosts that were domain members, mounted NoPac attacks against unpatched instances, and added a new account to Domain Admins if the host was a Domain Controller. According to GreyNoise, the attackers performed credential harvesting against 280 of the compromised hosts, exfiltrated secrets from 137 of them, and gained domain admin privileges in 12 instances. Of the 440 compromised deployments, 204 belonged to organizations in the education sector. Dozens of entities in the retail\u002Fprofessional services, real estate\u002Fhospitality, IT\u002FMSP, non-profit\u002Fcharity, library, and manufacturing\u002Futilities sectors were hit as well. Related: Critical NetScaler Vulnerability Exploited in Attacks Related: Organizations Warned of Cisco Secure FMC Exploitation Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender Related: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Critical NetScaler Vulnerability Exploited in Attacks4.1 Million Impacted by AdaptHealth Data BreachNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft DefenderFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksHelmGuard Raises $7.3 Million for Agentic GRC and SecurityAndroid’s September 2026 Updates Patch 180 VulnerabilitiesChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security AdvisoriesFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension Latest News Surfshark Systems Targeted by HackersAnthropic Says Russian Hackers Used Claude AI to Automate Malware EvasionMandiant Founder Kevin Mandia Joins Amazon BoardCybersecurity M&A Roundup: 33 Deals Announced in August 2026Anthropic Researcher Resigns With Warning About the Dangers of AI DevelopmentHacker Conversations: Vinnie Liu, Performer Turned RingmasterDeceptive Android Apps Exploit Google Play Early Access to Evade ReviewsWebinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveAmazon has elected Kevin Mandia to its Board of Directors.Gigamon has named Grant Yacomeni as Chief Information Security Officer.SSH Communications Security has appointed Lars Bell as Chief Executive Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fpapercut-flaws-exploited-in-ai-powered-attacks\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002FPaperCut-print-management.jpeg","2026-09-11T08:18:23+00:00","2026-09-11T10:00:28.425382+00:00",9,[18,21,24],{"name":19,"type":20},"Russian threat actor","threat_actor",{"name":22,"type":23},"PaperCut NG\u002FMF","product",{"name":25,"type":26},"AI","technology","6cbdd207-aaa1-4176-9534-e156b125e917",{"id":27,"icon":29,"name":30,"slug":31},null,"Nation-state","nation-state",[33,35,40,45],{"category":34},{"id":27,"icon":29,"name":30,"slug":31},{"category":36},{"id":37,"icon":29,"name":38,"slug":39},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,55],{"type":52,"value":53,"context":54},"cve","CVE-2026-82078","PaperCut NG\u002FMF vulnerability exploited in AI-powered attacks.",{"type":52,"value":56,"context":54},"CVE-2026-81578"]