Summary
- GreyNoise identified 59 UK victims in an AI-assisted campaign targeting vulnerable PaperCut NG/MF systems.
- The attacker used hundreds of AI agents during exploit development, targeting, credential harvesting, and compromise activity.
- PaperCut has now replaced its emergency patches with maintenance releases covering the exploited vulnerabilities.
An AI-assisted campaign targeting vulnerable PaperCut servers compromised hundreds of systems worldwide, with the UK accounting for one of the largest concentrations of identified victims outside the United States.
Threat intelligence company GreyNoise said the campaign compromised at least 440 instances of PaperCut NG and MF associated with 395 identified organisations across 48 countries. Its analysis counted 59 UK victims, alongside 31 in France and 31 in Spain, with further compromises spread across Europe and other regions.
The activity targeted CVE-2026-81578 and CVE-2026-82078, two vulnerabilities affecting PaperCut’s self-hosted print management software. PaperCut has acknowledged active exploitation and confirmed customer incidents. It has since replaced its emergency fixes with fully tested maintenance releases 26.0.5, 25.0.13, and 24.1.10.
What distinguishes the campaign is the degree of automation observed during the attack process. GreyNoise’s investigation concluded that a likely Russian-speaking malicious actor used hundreds of AI agents, alongside publicly available offensive security tools, while developing exploits, building target lists, harvesting credentials, and attacking exposed systems.
The attribution remains an assessment rather than a confirmed identity. GreyNoise said the campaign appeared opportunistic, and the attacker’s eventual objectives remain unclear. It has not established whether compromised access was intended for the actor’s own follow-on operations or for transfer to another group, nor whether affected organisations will subsequently face data theft, extortion, or ransomware.
The observed access, however, went beyond superficial scanning. GreyNoise said credentials were harvested from 280 victims, while operating-system or domain secrets were obtained from 147. Domain administrator privileges were reached at 12 organisations. In the UK, its data showed credential harvesting at 40 victims, access to operating-system or domain secrets at 20, and domain administrator access at three.
PaperCut NG and MF can occupy a particularly sensitive position inside corporate networks. The self-hosted Java applications commonly run on Windows servers with high privileges and can be integrated with Active Directory. A compromised print-management server can therefore provide an attacker with access well beyond the application itself when the surrounding environment and credentials permit it.
GreyNoise observed the actor creating a laboratory environment containing vulnerable PaperCut software and Active Directory infrastructure before moving into real-world exploitation. According to the company, the operation progressed from an empty workspace to remote code execution against a victim in under four hours and reached its first domain administrator account roughly two hours later. At one point, it observed 11 organisations compromised within 26 seconds.
Those figures provide an unusually concrete example of where AI-assisted offensive activity can alter the economics of exploitation. The underlying weaknesses were conventional software vulnerabilities, and the attack still depended on reachable, unpatched systems. AI appears to have accelerated the work around exploit development, validation, orchestration, and scale rather than creating a fundamentally new form of compromise.
The uneven results also temper broader claims about autonomous attacks. GreyNoise saw domain administrator access at only 12 of the 440 compromised instances and reported at least one target where a web application firewall stopped the activity. Automation increased speed and volume, but it did not remove the effects of patching, segmentation, access controls, or other defensive measures.
PaperCut’s latest maintenance releases address both vulnerabilities and supersede the emergency patches issued during the initial response. The company said reports of new compromises had slowed considerably over the previous week, although publicly reachable and unpatched servers continued to be targeted.
The campaign puts AI-enabled attack operations into a more measurable phase. Rather than hypothetical malware generation or chatbot-assisted reconnaissance, researchers were able to observe automated tooling being applied across development, target discovery, credential access, and compromise at substantial scale. The unresolved question is how quickly that model spreads beyond a technically capable operator into routine criminal infrastructure.





