A suspected cyber actor, believed to be Russian-speaking, has utilized artificial intelligence to exploit security vulnerabilities in PaperCut NG/MF software, compromising over 440 instances across 395 organizations in 48 countries. Reports from Blackpoint Cyber and GreyNoise have traced the activity to an IP address linked to recent unauthorized scanning and brute-force attack attempts. The attacks exploit two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, allowing for authentication bypass and remote code execution, primarily targeting educational institutions in countries like the U.S., U.K., and others.

The attacker's methodology includes delivering tools for Windows registry hive collection and using Java payloads to gather sensitive information. They have employed hundreds of AI agents powered by OpenAI Codex and other publicly available security tools to execute the attacks. Despite attempts to avoid certain countries, the attacks have been widespread, revealing the difficulty in controlling the reach of AI-driven campaigns.

GreyNoise reports that the attackers rapidly achieved remote code execution within hours of setting up their lab environment. The attack strategy involves iterative development, leveraging AI to not only develop exploits but also troubleshoot and refine the attack process. This approach significantly reduces the manual effort needed for such attacks, altering the economics of cybercrime.

The end goals of these attacks remain unclear, with possibilities ranging from selling access to other actors to deploying ransomware or stealing data. Blackpoint's investigation highlights the sophisticated use of AI in creating a robust exploitation pipeline that continuously adapts and improves.