Is Your Printer Running? You Better Go Catch It

Late this August over a hundred AI agents were used to compromise 395 organizations in 48 different countries, with education being the hardest hit sector, and the U.S the hardest hit country. The attack vector? PaperCut print management software.

A suspected Russian-speaking actor utilized AI agents built on OpenAI’s Codex and DeepSeek to develop exploits for CVE-2026-81578 and CVE-2026-82078. These vulnerabilities were publicly disclosed on August 27, and by August 31, the actor was already using agent-developed exploits in the wild.

The hacker was able to use CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution (RCE) chain) to infiltrate organizations across the education sector, gaining domain admin access in 12 separate instances. And in one of these twelve instances, as reported by GreyNoise,

“…the adversary went from initial access to full domain administrator in seven minutes.”

How does printer software lead to admin access? As further explained by GreyNoise, one of the first organizations to uncover the attack, the PaperCut versions affected, NG and MF, 

“…are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows and are usually domain-joined and integrated with Active Directory.”

A promising opportunity for malicious cyber attackers. The attacker behind this PaperCut cyber crime campaign began conducting research on potential victim organizations on August 31, and, just 4 hours later, achieved RCE on their first real-world victim.

This is exactly what AI-pacing advocates were worried about; the newfound ability to deploy hundreds of AI agents to continuously research, test, run code, adapt and retry, with minimal human intervention, has drastically shortened attack timelines. 

However, this ability would be essentially worthless without the technology to store massive amounts of AI memory, and coordinate tasks across multiple models. Having a shared memory layer that agents can consistently add to and draw information from helps keep things running smoothly, reducing the risk of context rot and time lost when stopping and redirecting agent actions.

Blackpoint Cyber provides an excellent summary of how persistent memory models were utilized during the PaperCut attacks to maximize speed and success: 

“…project context was carried between sessions, tools were run, files were updated, failures were worked through, and completed work, blockers, and next steps were continuously carried forward.”

It’s a near seamless process. With shared memory, users can now direct AI to perform entire campaigns, beginning to end, at scale. They can give models a blank workspace and end up with multiple successful runs in a matter of days. In the case of the PaperCut campaign, this multi-day timeline was a result of the threat actor holding off on initiating full scale attacks more so than actual model limitations. According to GreyNoise,

“…once the full campaign launched, [the adversary] compromised at least 11 organizations in 26 seconds.” 

These are inhuman cyber crime timelines. PaperCut started mitigation efforts the moment they were notified of a potential server compromise by a customer in the education sector, but by that point the MCA was already executing their campaign at scale.

Luckily for PaperCut, as they clearly express in their ongoing and informal incident report, their first victimized customer “had an excellent security and digital forensics and incident response team (DFIR).” Their customer’s immediate response to a suspected compromise, which included isolating the infected machine and preserving attack evidence, gave PaperCut an invaluable starting point with which to begin building their response. 

The aid this customer and others like them provided in PaperCut’s investigation and reconstruction of attack chains showcases the importance of strong incident response and endpoint detection and response (EDR) measures. Even in the face of a rapidly evolving digital ecosystem, traditional cybersecurity frameworks still provide an invaluable layer of defense. 

This is largely because the current advantage of advancing AI models is not just in their unique ability to combine overlooked vulnerabilities to create novel attack chains, but, as Blackpoint Cyber emphasizes, “the reduction of human effort” in every stage of the attack pipeline.

The threats AI models are bringing to the forefront of the cybersecurity conversation are not new in the sense that they are displaying inherently complex attack chains indecipherable and untraceable by human experts, but rather in the sense that they can find and execute predictable kinds of attacks in unpredictable ways, and at immense speeds. 

A great example of this is the fact that the agents’ lateral movements ran on NoPac (CVE-2021-42278 and CVE-2021-42287), which was patched five years ago. The AI succeeded by exploiting those old vulnerabilities – a cyber hygiene failure that predates AI by half a decade.

The PaperCut CEO also admitted an overlooked hygiene failure of their own - 

“One part of the chain leveraged a rarely used PaperCut feature that can look up card numbers from an external database. The attackers combined database-driver behavior, chained with arbitrary file-writing capabilities and Java class loading to place and execute their own payload...I also need to put my hand up here: the authentication-bypass part at the start of that chain came from code I personally have contributed to over the years.”

The belief that old code that has already survived years of internal testing is safe from exploitation is what leads to situations like this one, and is further proof of why continuous monitoring, rapid response, and preventative cybersecurity are some of the most vital digital defense tools in an organization’s arsenal. GreyNoise’s observations bolster this conclusion, as they state: 

“In at least one instance of targeting a perceived vulnerable PaperCut instance, Cloudflare’s Web Application Firewall (WAF) defeated the adversary. Fundamental hardening of environments still matters against AI-enabled threats.”

When organizations take hardening seriously, they can create a sort of unstoppable-force meets-immovable-object standoff. Because while AI can shorten attack timelines and increase the number of concurrent attacks being executed within a single campaign, that barrage of attacks is not going to get far against a well-established security environment.

Environments quite a few of the PaperCut compromise victims apparently possessed. With the help of some of the first campaign victims’ adept incident response, digital forensics, and EDR teams, PaperCut was able to send out a series of emergency patches relatively quickly.

The company has yet to release a post-incident report, but for now it seems the initial damages wrought by this attack were minimal. It’s possible this was just a research or test campaign, one designed to gather breach information for another group to act on (a theory that seems to be supported by the attacker’s lack of action after gaining admin access), and similarly led agentic attacks will prove far more devastating in future occurrences.

However, without full knowledge of the post-incident impact, this remains cautious speculation. As it currently stands, AI does not yet pose a threat cybersecurity teams cannot meet when equipped with strong incident response and preventative frameworks. As emphasized by GreyNoise in their final key takeaway, 

“Organizations are not helpless against agentic attacks and traditional hardening does have a positive impact on the security posture of an organization.”

‍There is a lot of panic concerning the advancement of frontier AI, and the possibility of a digital world run primarily by AI agents, where attacks orchestrated by AI swarms are commonplace. And while those concerns deserve to be addressed and properly prepared for, it’s important to remember that AI is not there yet, and might never be, despite what AI CEOs are claiming.

Traditional hardening of cybersecurity systems is still a viable defense, and organizations who engage in routine security maintenance, who keep up with current cybersecurity best practices, are less likely to be strongly impacted by the increase in AI attacks. 

Sources

https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf

https://blackpointcyber.com/blog/death-by-a-thousand-papercuts-ai-driven-exploitation-at-scale/

https://www.papercut.com/blog/news/behind-the-scenes-august-security-incident/

https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html

https://www.theregister.com/security/2026/09/10/hundreds-of-ai-agents-helped-papercut-attacker-hit-395-orgs-and-some-went-off-script/5295650?utm_source=tldrinfosec  

Next
Next

Chrome, CVEs, and Search Engine Security