AI Weekly Malaysia

Back to items Summaries

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

ID
23463
Status
summarized
Published
11 Sep 2026, 2:46 PM
Fetched
11 Sep 2026, 4:09 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
11 Sep 2026, 4:10 PM
Tags
Audience
developersai_agent_userssaas_founders

What happened

PaperCut released maintenance releases (versions 26.0.5, 25.0.13, 24.1.10) that supersede three emergency patches for two actively exploited flaws, CVE-2026-81578 and CVE-2026-82078, which allow authentication bypass and arbitrary code execution. GreyNoise and Blackpoint Cyber reported a suspected Russian-speaking threat actor used hundreds of AI agents powered by OpenAI's Codex harness and a DeepSeek model to breach at least 395 organizations across 48 countries, mostly U.S. education sector, while deliberately avoiding targets in Russia, China, Hong Kong, Thailand, Iran, and 23 others.

Why it matters

If you run PaperCut NG/MF on any emergency patch build, move to the maintenance release now—these are fully QA-tested replacements, not incremental fixes. Beyond patching, the attack chain is a concrete example of AI agents being used to scale exploitation across hundreds of targets with geographic avoidance logic, which is worth understanding if you build or defend against automated agent systems.

Discussion angle

The use of hundreds of AI agents (Codex + DeepSeek) to automate breach operations at scale with built-in geo-avoidance is a preview of how offensive automation changes the economics of targeting—what does this mean for defenders who are also adopting AI agents?

Top