Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

AI-Powered Cyber Attack: The PaperCut Flaws and the Hunt for a Suspected Russian-Speaking Actor




A recent cyber attack on PaperCut NG/MF has highlighted the significant impact of artificial intelligence (AI) on cyber attacks. A suspected Russian-speaking cyber actor has been attributed to the use of AI in devising exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and breaking into hundreds of instances. The attack, which exploited CVE-2026-81578 and CVE-2026-82078, primarily targeted the education sector in various countries, and used OpenAI Codex, a DeepSeek model, and publicly available offensive security tools to create hundreds of AI agents that compromised PaperCut MF/NG instances hosted by 395 identified victim organizations in 48 countries. The campaign highlights the significant impact of AI on the economics of cyber attacks and the importance of threat intelligence and cybersecurity efforts.

  • The latest cyber attack on PaperCut NG/MF used AI to devise exploits targeting security flaws and break into hundreds of instances.
  • The attack originated from an IP address linked to unauthorized port scanning and brute-force attack attempts.
  • The attackers exploited CVE-2026-81578 and CVE-2026-82078 vulnerabilities, primarily targeting the education sector in multiple countries.
  • The AI-powered campaign used OpenAI Codex and publicly available offensive security tools to create hundreds of AI agents that compromised 395 victim organizations in 48 countries.
  • The attackers gained domain administrator access in seconds, and the exact end goal of the campaign remains unclear.
  • The use of AI highlights the significant impact on the economics of cyber attacks, reducing human effort required to research and develop exploits.
  • The campaign demonstrates the importance of threat intelligence and the need for organizations to prioritize their cybersecurity efforts.



  • The latest news in the world of cybersecurity has once again highlighted the significant impact of artificial intelligence (AI) on cyber attacks. According to recent reports, a suspected Russian-speaking cyber actor has been attributed to the use of AI in devising exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and breaking into hundreds of instances.

    The cyber attack, which has been dubbed as one of the most significant in recent times, is believed to have originated from an IP address that has been linked to unauthorized port scanning and brute-force attack attempts in recent weeks. The same IP address was also flagged by Arctic Wolf in connection with the exploitation activity last week.

    The attack in question exploited CVE-2026-81578 and CVE-2026-82078, a combination of an authentication bypass and remote code execution chain, primarily targeting the education sector in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.

    The attackers used OpenAI Codex, a DeepSeek model, and publicly available offensive security tools such as Mimikatz, SharpHound, Certipy, Rubeus, and Impacket to create hundreds of AI agents that were used to compromise PaperCut MF/NG instances hosted by 395 identified victim organizations in 48 countries.

    The campaign, which was reportedly swift in its execution, saw the attackers gaining domain administrator access against at least 12 victim organizations in a matter of seconds. However, the exact end goal of the campaign remains unclear, with researchers speculating that the attacker may be solely focused on access development to be handed off to other affiliated actors or may directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment.

    The use of AI in this campaign highlights the significant impact it can have on the economics of cyber attacks. According to Blackpoint, the strongest AI impact in this campaign was not a novel exploit technique but rather the reduction of human effort required to research, develop, debug, classify, track, retry, and continuously improve exploitation across hundreds of real systems.

    The AI-powered campaign also demonstrates the importance of threat intelligence and the role it plays in understanding the threat actor's methodology. The recovered source code, which acted as a funnel that merged multiple source lists, geolocated candidates, and filtered them by country, applying the aforementioned exclusion policy, and identifying live PaperCut systems before moving to the next stage, provides valuable insights into the threat actor's workflow.

    Furthermore, the use of AI in this campaign highlights the need for organizations to prioritize their cybersecurity efforts. The fact that the attackers were able to compromise hundreds of instances in a matter of seconds highlights the importance of keeping software up-to-date and implementing robust security measures.

    In conclusion, the recent cyber attack on PaperCut NG/MF highlights the significant impact of AI on cyber attacks. The use of AI in this campaign demonstrates the importance of threat intelligence, the need for organizations to prioritize their cybersecurity efforts, and the significant impact it can have on the economics of cyber attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/AI-Powered-Cyber-Attack-The-PaperCut-Flaws-and-the-Hunt-for-a-Suspected-Russian-Speaking-Actor-ehn.shtml

  • https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-81578

  • https://www.cvedetails.com/cve/CVE-2026-81578/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-82078

  • https://www.cvedetails.com/cve/CVE-2026-82078/


  • Published: Thu Sep 10 11:41:55 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us