Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide

A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print management software and compromise at least 440 servers across 395 organizations in 48 countries.
Security researchers at GreyNoise identified the campaign through their Global Observation Grid, a network of sensors that captures live attacker activity on controlled infrastructure.
The malicious actor operated from IP address 45.142.193.132, which GreyNoise had flagged since early July 2026 for probing internet-facing systems from vendors including Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.
On August 31, 2026, this infrastructure pivoted toward two PaperCut vulnerabilities, CVE-2026-81578 and CVE-2026-82078 , an authentication bypass and an unsafe reflection remote code execution flaw, respectively.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in