Damus
Ox HaK profile picture
Ox HaK
@oxhak
GreyNoise reports that a Russian-speaking threat actor used AI to build, test, and deploy exploits for two PaperCut NG/MF zero-days, CVE-2026-82078 and CVE-2026-81578. The flaws enabled remote unauthenticated attackers to bypass authentication and execute arbitrary code; patches were released on August 28 after disclosure the previous day.

The campaign compromised 440 deployments operated by 395 organizations in 48 countries, targeting remote code execution and credential theft. Attackers harvested credentials on 280 hosts, exfiltrated secrets from 137, and obtained domain-admin privileges in 12 cases. Education organizations accounted for 204 compromised deployments, while follow-on ransomware or data theft remains uncertain.

https://www.securityweek.com/papercut-flaws-exploited-in-ai-powered-attacks/