Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Climate hazards disrupted school for 1 in 10 students in 2025: UNICEF | Climate Crisis News

    September 10, 2026

    Why are MPs voting on assisted dying again?

    September 10, 2026

    The Guardian view on the prisons crisis: moving men into women’s jails is not the answer | Editorial

    September 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Climate hazards disrupted school for 1 in 10 students in 2025: UNICEF | Climate Crisis News
    • Why are MPs voting on assisted dying again?
    • The Guardian view on the prisons crisis: moving men into women’s jails is not the answer | Editorial
    • Anthropic reveals rogue AI agents hate CAPTCHAs, just like you
    • AI-powered attack exploited PaperCut flaws to hack 395 organizations
    • Nasdaq Invests $100M In Kraken Parent Company: Report
    • Scientists discover a hidden immune signal that helps spinal cords regrow
    • How California Is Kicking Its Natural Gas Habit
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AI-powered attack exploited PaperCut flaws to hack 395 organizations

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 10, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.

    The agents were tasked with building, testing, and refining exploits for CVE-2026-81578 and CVE-2026-82078, both security flaws affecting PaperCut Software and flagged as actively exploited earlier this month.

    Attack and threat intelligence company GreyNoise says the campaign began on August 31, combining OpenAI’s Codex and DeepSeek models with commodity offensive tools.

    The AI agents also generated target lists through the Netlas internet scanning and discovery platform.

    GreyNoise data indicates that the operation compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries.

    The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and obtained administrator privileges at 12 organizations.

    Most of the victims were in the education sector, accounting for roughly half of all breaches. The United States was the most targeted country, followed by the United Kingdom, France, Spain, and Canada.

    According to GreyNoise, the threat actor specified a list of countries to avoid, including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa. However, the agents did not consistently follow these rules.

    GreyNoise underlines that AI enables attackers to launch rapid attacks that leave defenders with very tight response margins.

    “The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours, first domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds,” GreyNoise notes.

    “In one instance, the adversary went from initial access to full domain administrator in seven minutes against a high school in the United States.”

    Attack timeline
    Attack timeline
    Source: GreyNoise

    The researchers observed three attack paths after exploiting the PaperCut flaws:

    1. Dumping LSASS memory and registry secrets from domain-joined PaperCut servers, then passing recovered credential hashes to domain controllers (“pass-the-hash” attack).
    2. Using the “noPac” attack against environments still vulnerable to CVE-2021-42278 and CVE-2021-42287.
    3. Directly adding a newly created account to Domain Admins when PaperCut ran on a domain controller or under a domain administrator service account.

    In all cases, the attackers used the DCSync post-exploitation technique to obtain a complete NTDS.DIT dump with domain credentials.

    The attacker’s toolkit includes Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and custom Rust credential-collection utilities.

    GreyNoise could not determine the attacker’s campaign objective, but the access could be used for data theft or ransomware operations.

    System administrators are advised to apply PaperCut’s emergency security updates addressing CVE-2026-81578 and CVE-2026-82078 immediately, and follow the vendor’s recommendations in this bulletin.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    AIpowered attack Exploited flaws hack Organizations PaperCut
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

    Anthropic Researcher Resigns With Warning About the Dangers of AI Development

    Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster

    Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

    Microsoft says September updates fix mouse settings reset issues

    10 most critical LLM vulnerabilities

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Climate hazards disrupted school for 1 in 10 students in 2025: UNICEF | Climate Crisis News

    September 10, 2026

    Why are MPs voting on assisted dying again?

    September 10, 2026

    The Guardian view on the prisons crisis: moving men into women’s jails is not the answer | Editorial

    September 10, 2026

    Anthropic reveals rogue AI agents hate CAPTCHAs, just like you

    September 10, 2026
    Latest Posts

    Mathematicians prove perfectly fair elections are impossible

    August 2, 2026

    Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

    August 2, 2026

    Foldables are sort of boring now — and that’s great news for Apple

    August 2, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Climate hazards disrupted school for 1 in 10 students in 2025: UNICEF | Climate Crisis News

    September 10, 2026

    Why are MPs voting on assisted dying again?

    September 10, 2026

    The Guardian view on the prisons crisis: moving men into women’s jails is not the answer | Editorial

    September 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.