A coordinated cyber‑attack that used generative‑AI tools to exploit two zero‑day vulnerabilities in PaperCut NG/MF print‑management software has compromised 440 server instances across 395 organizations in 48 countries, according to threat‑intelligence firm GreyNoise.

The vulnerabilities, identified as CVE‑2026‑81578 and CVE‑2026‑82078, were disclosed on 27 August 2026. CVE‑2026‑81578 is an improper access‑control flaw that allows unauthenticated users to modify system configuration before authentication is verified. CVE‑2026‑82078 is an unsafe dynamic class‑loading issue that permits arbitrary Java bytecode execution. Both defects can be triggered remotely and enable attackers to run code with the privileges of the PaperCut service.

GreyNoise reports that the campaign began on 31 August 2026. The attacker, believed to be a Russian‑speaking threat actor, employed AI agents built with OpenAI’s Codex and DeepSeek models to automatically discover, test, and deploy exploits against vulnerable PaperCut installations. The AI system also used the Netlas internet‑scanning platform to generate target lists, allowing the attacker to identify and attack vulnerable servers with minimal manual effort.

During the campaign, the actor used three distinct attack paths: 1. Harvesting LSASS process memory and registry secrets from domain‑joined hosts. 2. Launching NoPac attacks against unpatched instances. 3. Adding a new account to the Domain Admins group on domain controllers.

GreyNoise data shows that the attacker harvested credentials from 280 compromised hosts, exfiltrated secrets from 137, and achieved Domain Admin privileges in 12 organizations. The fastest privilege escalation occurred within five minutes of initial compromise. The actor explicitly attempted to avoid targeting entities in 28 identified countries, but the observed victimology indicates that this restraint was not fully effective.

Sector analysis reveals that 204 of the affected deployments belong to educational institutions. Other impacted sectors include retail and professional services, real‑estate and hospitality, IT and managed service providers, non‑profit and charity organizations, libraries, and manufacturing and utilities.

The use of AI to orchestrate the campaign allowed the attacker to compromise some environments in minutes and even seconds, a speed that would be difficult to achieve with manual exploitation. GreyNoise notes that it is unclear whether the actor’s primary goal is to develop and sell access to other groups or to use the compromised systems for follow‑on objectives such as data theft or ransomware deployment.

The vulnerabilities were patched the day after disclosure, but GreyNoise indicates that the initial patch was bypassed, prompting a second emergency patch. Organizations that had not applied the latest updates remain at risk.

Cybersecurity experts advise that all PaperCut NG/MF users verify that they are running the latest version and that they have applied the emergency patches for both CVE‑2026‑81578 and CVE‑2026‑82078. In addition, organizations should monitor for signs of unauthorized code execution, credential harvesting, and unusual domain‑controller activity.

The incident underscores the growing trend of threat actors leveraging generative‑AI systems to automate vulnerability exploitation at scale. While the specific motivations of the Russian‑speaking actor remain uncertain, the attack demonstrates that AI can accelerate the discovery and deployment of zero‑day exploits, increasing the potential impact on a wide range of industries.

In the coming weeks, security teams should expect continued monitoring of PaperCut deployments, potential follow‑on investigations into compromised accounts, and further analysis of the AI‑driven techniques used in this campaign. The incident serves as a reminder that rapid patching and vigilant monitoring are essential defenses against AI‑enhanced cyber threats.