AI agents help PaperCut attacker hit 395 organizations
GreyNoise's 9 September 2026 blog says a likely Russian-speaking actor used hundreds of AI agents to compromise at least 440 PaperCut MF/NG instances at 395 organizations in 48 countries. Once the campaign launched, at least 11 organizations were hit in 26 seconds. Domain admin landed on only 12 of 440 hosts.

GreyNoise, in a 9 September 2026 blog titled "Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF," says a likely Russian-speaking actor used hundreds of AI agents to compromise at least 440 PaperCut MF and NG instances. GreyNoise identified 395 victim organizations in 48 countries. The campaign ran from 45.142.193.132, an address GreyNoise has tracked since early July.
This is a threat-intel disclosure from GreyNoise sensors. It is not a new PaperCut CVE announcement. The bugs themselves, CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe class loading), were disclosed in late August and chained for pre-authentication remote code execution.
The agents sat on an OpenAI Codex harness with a DeepSeek model. GreyNoise stresses the language model in the loop was DeepSeek, not OpenAI models. The toolkit also included Mimikatz, SharpHound, Certipy, Rubeus, and Impacket. The operator went from an empty workspace to first real-victim remote code execution in under four hours.
Once the full campaign launched, GreyNoise says at least 11 organizations were compromised in 26 seconds. On one US high school, initial access to domain admin took seven minutes. Domain admin still landed on only 12 of the 440 hosts.
Education made up 204 of those 440 instances. The actor kept an exclusion list of 28 countries and then sometimes ignored it, which is why GreyNoise titled the post Agents Gone Wild. GreyNoise says the end goal is still unclear (initial-access broker versus direct ransomware or theft) and that it partnered with incident-response firms on victim notification.
PaperCut's urgent advisory names the two CVEs and now points customers to maintenance builds 24.1.10, 25.0.13, and 26.0.5. Arctic Wolf said those same version numbers are Emergency Patch Release 3, and that Release 1 or 2 alone is not enough. Arctic Wolf also said CISA added both CVEs to the Known Exploited Vulnerabilities catalog as of 31 August.
PaperCut says it has not independently verified third-party indicators, including GreyNoise's, because they did not come from reports made to PaperCut.
Cyberpresso already covered the emergency patch itself. The scale-up sits next to other AI-enabled intrusion notes, including Anthropic's September 2026 threat report, plus internet-facing management-plane cases such as WatchGuard Firebox RCE in ransomware and Cisco Secure FMC under active attack.
If you still run PaperCut NG or MF, move to 24.1.10, 25.0.13, or 26.0.5, pull the Application Server off the public internet, and hunt your own logs for GreyNoise's 45.142.193.132 and hive-dump artifacts. PaperCut's third-party indicator caveat means treat those addresses as a hunt list, not as a closed vendor confirmation, and do not wait for a ransomware payload that GreyNoise has not attributed.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free