AI Weekly Malaysia

Back to items Summaries

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

ID
23163
Status
summarized
Published
10 Sep 2026, 7:41 PM
Fetched
10 Sep 2026, 9:12 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
10 Sep 2026, 9:13 PM
Tags
Audience
developersai_agent_usersai_ml_learnerssaas_founders

What happened

A suspected Russian-speaking threat actor exploited CVE-2026-81578 (auth bypass) and CVE-2026-82078 (RCE) in PaperCut NG/MF, using hundreds of AI agents powered by OpenAI Codex and a DeepSeek model alongside tools like Mimikatz, SharpHound, Certipy, and Impacket to compromise 440+ instances across 395 organizations in 48 countries. GreyNoise reports the attacker built a self-hosted lab with vulnerable PaperCut and Active Directory, used Netlas.io for target enumeration, and deliberately avoided entities in 28 countries. Post-exploitation included registry hive collection, Meterpreter payloads, and host/user enumeration.

Why it matters

This is one of the first documented cases of AI agents being orchestrated at scale (hundreds) for offensive security operations — not a demo, but a real campaign with 440+ victims. If you run PaperCut NG/MF on internet-facing servers, patch CVE-2026-81578 and CVE-2026-82078 immediately and check for the IP 45.142.193.132 in your logs. For AI agent builders, this demonstrates that agent orchestration patterns you use for automation can be trivially repurposed for mass exploitation, raising the stakes on agent safety and access-scoping decisions.

Discussion angle

The attacker used hundreds of AI agents (OpenAI Codex + DeepSeek) as a parallelized exploitation workforce — what does this tell us about how agent orchestration frameworks lower the barrier to mass offensive operations, and what guardrails should agent platform providers realistically be expected to enforce?

Top