AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor used AI-powered agents to exploit two vulnerabilities in PaperCut NG/MF servers, compromising at least 440 instances across 395 organizations globally. The campaign rapidly developed and launched exploits for CVE-2026-81578 and CVE-2026-82078, primarily targeting the education sector. Attackers harvested credentials, obtained domain secrets, and achieved administrator privileges in multiple organizations. The campaign employed advanced post-exploitation techniques including pass-the-hash, noPac attacks, and DCSync to extract domain credentials. The attacker toolkit included well-known offensive tools and custom utilities. System administrators are urged to apply PaperCut's emergency security updates immediately. The attack demonstrated unprecedented speed and automation enabled by AI, significantly reducing defenders' response time.
AI Analysis
Technical Summary
A Russian-speaking threat actor leveraged hundreds of AI agents combining OpenAI Codex, DeepSeek models, and commodity offensive tools to build, test, and refine exploits targeting PaperCut NG/MF vulnerabilities CVE-2026-81578 and CVE-2026-82078. The campaign began on August 31, 2026, and compromised at least 440 PaperCut instances linked to 395 organizations in 48 countries, predominantly in the education sector. The attackers harvested credentials from 280 victims, obtained OS or domain secrets from 147, and gained administrator privileges in 12 organizations. Attack paths included dumping LSASS memory, pass-the-hash attacks, noPac attacks against legacy vulnerabilities, and direct domain admin account creation. Post-exploitation used DCSync to extract full NTDS.DIT dumps. The attacker toolkit included Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust tools. The campaign's objective remains unclear but access could facilitate data theft or ransomware. PaperCut has issued emergency security updates addressing these vulnerabilities.
Potential Impact
The campaign resulted in widespread compromise of PaperCut NG/MF servers, credential theft, and domain-level access in multiple organizations. Attackers obtained administrator privileges in at least 12 organizations, enabling potential full domain control. The breach exposed operating system and domain secrets, increasing risk of further lateral movement and persistent access. The rapid AI-driven attack automation drastically shortened response windows for defenders. The compromised credentials and domain secrets could be used for data exfiltration, ransomware deployment, or other malicious activities.
Mitigation Recommendations
PaperCut has released emergency security updates addressing CVE-2026-81578 and CVE-2026-82078. System administrators must apply these patches immediately. Following the vendor's official recommendations in the security bulletin is critical. No indication exists that the vulnerabilities are mitigated without patching. Given the rapid exploitation and post-compromise techniques, organizations should assume compromise if vulnerable and conduct thorough incident response.
AI-powered attack exploited PaperCut flaws to hack 395 organizations
Description
A threat actor used AI-powered agents to exploit two vulnerabilities in PaperCut NG/MF servers, compromising at least 440 instances across 395 organizations globally. The campaign rapidly developed and launched exploits for CVE-2026-81578 and CVE-2026-82078, primarily targeting the education sector. Attackers harvested credentials, obtained domain secrets, and achieved administrator privileges in multiple organizations. The campaign employed advanced post-exploitation techniques including pass-the-hash, noPac attacks, and DCSync to extract domain credentials. The attacker toolkit included well-known offensive tools and custom utilities. System administrators are urged to apply PaperCut's emergency security updates immediately. The attack demonstrated unprecedented speed and automation enabled by AI, significantly reducing defenders' response time.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A Russian-speaking threat actor leveraged hundreds of AI agents combining OpenAI Codex, DeepSeek models, and commodity offensive tools to build, test, and refine exploits targeting PaperCut NG/MF vulnerabilities CVE-2026-81578 and CVE-2026-82078. The campaign began on August 31, 2026, and compromised at least 440 PaperCut instances linked to 395 organizations in 48 countries, predominantly in the education sector. The attackers harvested credentials from 280 victims, obtained OS or domain secrets from 147, and gained administrator privileges in 12 organizations. Attack paths included dumping LSASS memory, pass-the-hash attacks, noPac attacks against legacy vulnerabilities, and direct domain admin account creation. Post-exploitation used DCSync to extract full NTDS.DIT dumps. The attacker toolkit included Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust tools. The campaign's objective remains unclear but access could facilitate data theft or ransomware. PaperCut has issued emergency security updates addressing these vulnerabilities.
Potential Impact
The campaign resulted in widespread compromise of PaperCut NG/MF servers, credential theft, and domain-level access in multiple organizations. Attackers obtained administrator privileges in at least 12 organizations, enabling potential full domain control. The breach exposed operating system and domain secrets, increasing risk of further lateral movement and persistent access. The rapid AI-driven attack automation drastically shortened response windows for defenders. The compromised credentials and domain secrets could be used for data exfiltration, ransomware deployment, or other malicious activities.
Mitigation Recommendations
PaperCut has released emergency security updates addressing CVE-2026-81578 and CVE-2026-82078. System administrators must apply these patches immediately. Following the vendor's official recommendations in the security bulletin is critical. No indication exists that the vulnerabilities are mitigated without patching. Given the rapid exploitation and post-compromise techniques, organizations should assume compromise if vulnerable and conduct thorough incident response.
Technical Details
- Classification
- {"confidence":0.59,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6aa2dc83f76d26f0255729d9
Added to database: 09/10/2026, 16:36:19 UTC
Last enriched: 09/10/2026, 16:36:26 UTC
Last updated: 09/10/2026, 16:37:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.