CyberSecurityNews·3 min read

Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide

G
Guru Baran
Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide
Dive DeeperCreate a free account to unlock

A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print management software and compromise at least 440 servers across 395 organizations in 48 countries.

Security researchers at GreyNoise identified the campaign through their Global Observation Grid, a network of sensors that captures live attacker activity on controlled infrastructure.

The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for probing internet-facing systems from vendors including Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.

On August 31, 2026, this infrastructure pivoted toward two PaperCut vulnerabilities, CVE-2026-81578 and CVE-2026-82078 , an authentication bypass and an unsafe reflection remote code execution flaw, respectively.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in