
PaperCut has become the target of an attack campaign powered by hundreds of AI agents. The operation compromised at least 440 PaperCut instances across 395 organizations in 48 countries. PaperCut develops software that helps organizations manage printing across their networks. Attackers exploited two newly disclosed flaws to gain access without authentication.
However, the breach stands out because AI agents handled major parts of the attack. The attacker used them to develop, test, and deploy exploits against vulnerable servers. Because of this, the operation reached multiple organizations at extraordinary speed. The incident further proves how AI could expand the reach of cyberattacks.
AI Agents Breached 395 Firms
On August 31st, a likely Russian-speaking actor used AI to develop and test exploits against PaperCut NG and MF. The actor then deployed hundreds of AI agents against potential targets.
In addition, the campaign moved rapidly. The actor reached remote code execution against a real victim in under four hours. Two hours later, the actor reached domain administrator access. During the wider campaign, the actor compromised 11 organizations within 26 seconds. In one case, domain administrator access followed within seven minutes.
PaperCut Became the Entry Point
Furthermore, two vulnerabilities created the opening. CVE-2026-81578 involves improper access control in the web management interface. CVE-2026-82078 involves unsafe dynamic class loading in database connection utilities. Attackers could chain both flaws to achieve remote code execution without authentication.
First, the actor built a private lab containing vulnerable PaperCut software and an Active Directory server. Next, the actor tested the exploits before scanning for potential targets. Then, AI agents helped pursue targets through parallel operations.
AI Changed the Scale
Notably, the campaign matters because AI agents handled several attack tasks simultaneously. They helped develop exploits, test them, identify targets, and launch attacks. As a result, one operator could pursue numerous systems without manually controlling every step.
However, the approach did not succeed everywhere. GreyNoise observed domain administrator access at 12 victim organizations. Cloudflare’s Web Application Firewall also blocked an attempted compromise. Even so, the campaign demonstrated how automation can expand exploitation across many targets.
Defenders Must Move Faster
PaperCut disclosed the vulnerabilities on August 27 and warned about active exploitation. In addition, the company released emergency patches and later published maintenance releases on September 10. Now, organizations should install supported updates and restrict public access to affected PaperCut Application Servers.
However, the wider concern extends beyond PaperCut. Attackers can combine AI agents with security tools and newly disclosed vulnerabilities. Therefore, organizations need timely patching, restricted exposure, and monitoring for suspicious activity.
Ultimately, AI does not need to replace attackers to change cyber operations. Instead, agents can handle repetitive tasks while humans direct the broader campaign. That combination could give attackers more opportunities to exploit vulnerable software at scale.
