A suspected Russian-speaking attacker has used hundreds of autonomous AI agents to exploit two newly disclosed vulnerabilities in PaperCut NG/MF print management software, compromising 440 servers across 395 organizations in 48 countries and collapsing the traditional cyber kill chain into a matter of minutes[1][9][15]. The campaign, already dubbed the Papercut AI swarm attack by researchers, demonstrates how agentic AI can now independently drive reconnaissance, exploitation, lateral movement and credential theft at global scale[1][2][4].
The intrusions hinge on a pair of high-impact flaws tracked as CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF, which together allow unauthenticated attackers to turn an internet-exposed application server into a remote code execution beachhead[9][11][12]. CVE-2026-81578 is an improper access control bug in the web management interface that enables authentication bypass and configuration changes by unauthenticated remote attackers, earning a CVSS v3 score of 8.8 for its ease of exploitation and high impact[9][10]. CVE-2026-82078 is an unsafe dynamic class loading issue in the database connection utilities that lets an attacker manipulate driver configuration to execute arbitrary Java bytecode in the PaperCut server’s context, providing full server-level RCE once basic access is obtained[6][11]. Both vulnerabilities have public proof-of-concept exploits and are now listed in the CISA Known Exploited Vulnerabilities catalog, raising the urgency for rapid patching[9][11][13].
PaperCut Software disclosed the two flaws in a security bulletin on August 27, 2026 and urged customers to upgrade to fixed builds—PaperCut NG and MF versions 24.1.9, 25.0.12 and 26.0.4—while hardening server exposure and reviewing logs for suspicious activity[9][12]. Threat intelligence write-ups note that chaining CVE-2026-81578 and CVE-2026-82078 effectively turns unauthenticated HTTP requests into arbitrary Java code execution, making vulnerable print servers ideal launchpads for broader network compromise[12][14][15]. Despite the availability of patches, GreyNoise telemetry suggests hundreds of unpatched systems remained exposed on August 31, giving the attacker a wide attack surface for their AI-driven campaign[1][15].
According to researchers at GreyNoise, the adversary first built a self-hosted lab environment to develop and test exploitation chains for both CVEs, then orchestrated hundreds of AI agents—some powered by an OpenAI Codex harness and a DeepSeek model—to run mass reconnaissance, exploit vulnerable servers, harvest credentials and pivot into internal networks[1][2][11]. These agents were tasked with discrete kill-chain functions, from scanning for exposed PaperCut instances and validating CVE-2026-81578 exposure, to deploying CVE-2026-82078 payloads and escalating privileges once footholds were established[1][9][11]. In at least one U.S. high school network, the campaign reportedly moved from initial access on a PaperCut server to full domain administrator privileges in about seven minutes, underscoring how agentic automation can compress what used to be a multi-stage operation into a near-real-time event[2][4][5].
The impact has been felt most acutely in the education sector, where many organizations rely on PaperCut NG/MF for centralized print management but often expose those servers to the internet with limited segmentation[1][2][14]. GreyNoise and other observers report that 440 PaperCut deployments tied to 395 distinct victims were compromised, with nearly half of those organizations located in the United States and a significant concentration in K–12 and higher education environments[1][14][15]. Once the AI agents gained access, they used the print servers as pivots to harvest credentials, enumerate domain trusts and move laterally, in some cases spawning Meterpreter payloads and other post-exploitation tooling to deepen their foothold[9][11][15]. While full details of data theft or extortion outcomes have not yet been made public, the speed and scale of the intrusions suggest that traditional detection and response workflows were outpaced by automated attack logic[1][2][7].
For defenders, the Papercut AI swarm attack is a stark illustration of how the cyber kill chain is being reshaped by autonomous systems that can iterate, learn from failures and launch parallel operations without direct human micromanagement[1][3][11]. Many of the tradecraft elements mirror earlier exploitation of PaperCut CVE-2023-27350, which CISA warned about in 2023, but the addition of agentic AI dramatically reduces the time defenders have to notice anomalies such as unusual access to setup pages, odd child processes from PaperCut executables or mass configuration changes in server settings[13][14]. Security teams are being urged to assume that any internet-reachable PaperCut NG/MF instance is now a high-value target, prioritize upgrades to patched versions, remove direct exposure where possible, and monitor for indicators tied to CVE-2026-81578 and CVE-2026-82078 exploitation[9][11][12].
Experts say the campaign should also prompt broader strategic shifts, including integrating AI-aware threat models into risk assessments and rehearsing incident response scenarios where dozens or hundreds of coordinated agents attack in parallel[1][3][14]. Network defenders can draw on CISA’s prior PaperCut guidance for detection baselines—such as watching for unusual traffic to management endpoints, monitoring for unexpected child processes from PaperCut services and scrutinizing server logs for anomalous admin actions—but must assume attacks will now unfold far faster than human operators can manually triage[13][14]. As Papercut’s AI swarm attack shows, the next wave of offensive operations will blur the line between automated penetration testing and real-world intrusion campaigns, forcing organizations to treat print management servers and other “utility” services as critical security infrastructure rather than background IT plumbing[1][11][15].
References
- Agents Gone Wild: An AI-Orchestrated Global Campaign …
- Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
- AI agent swarm incidents: autonomous penetration testing tools …
- The CyberSec Guru on X
- The CyberSec Guru on X: ” PAPER CUT IS UNDER ATTACK BY AI …
- CVE-2026-82078
- L’Actu International du Jour Hacking, Cybersécurité, RGPD …
- CVE-2026-81578 – Exploits & Severity – Feedly
- CVE-2026-81578
- CVE-2026-82078 – Exploits & Severity
- CVE Alerts, APT Tracking & Threat Intelligence | Techgines Blog
- Malicious Actors Exploit CVE-2023-27350 in PaperCut MF …
- AI-Orchestrated PaperCut Attack Compromises 440 …
- FediSecfeeds