PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
- ID
- 23463
- Status
- summarized
- Published
- 11 Sep 2026, 2:46 PM
- Fetched
- 11 Sep 2026, 4:09 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 11 Sep 2026, 4:10 PM
- Tags
- Audience
- developersai_agent_userssaas_founders
What happened
PaperCut released maintenance releases (versions 26.0.5, 25.0.13, 24.1.10) that supersede three emergency patches for two actively exploited flaws, CVE-2026-81578 and CVE-2026-82078, which allow authentication bypass and arbitrary code execution. GreyNoise and Blackpoint Cyber reported a suspected Russian-speaking threat actor used hundreds of AI agents powered by OpenAI's Codex harness and a DeepSeek model to breach at least 395 organizations across 48 countries, mostly U.S. education sector, while deliberately avoiding targets in Russia, China, Hong Kong, Thailand, Iran, and 23 others.
Why it matters
If you run PaperCut NG/MF on any emergency patch build, move to the maintenance release now—these are fully QA-tested replacements, not incremental fixes. Beyond patching, the attack chain is a concrete example of AI agents being used to scale exploitation across hundreds of targets with geographic avoidance logic, which is worth understanding if you build or defend against automated agent systems.
Discussion angle
The use of hundreds of AI agents (Codex + DeepSeek) to automate breach operations at scale with built-in geo-avoidance is a preview of how offensive automation changes the economics of targeting—what does this mean for defenders who are also adopting AI agents?