Hackers Deploy Multiple AI Agents to Target PaperCut Zero-Day Vulnerabilities

Active Cyberattack Campaign Targets PaperCut Software

Cybersecurity researchers from Blackpoint Cyber and GreyNoise have uncovered an active cyberattack campaign targeting users of PaperCut NG and PaperCut MF, self-hosted print management solutions commonly utilized for printing and scanning services. The attackers are exploiting vulnerabilities associated with the Application Servers of these products, specifically the flaws identified as CVE-2026-81578 and CVE-2026-82078.

Previously, reports indicated that the PaperCut NG/MF Application Servers faced ongoing attacks that led the respective vendor to issue emergency patches addressing these two zero-day vulnerabilities. These flaws permit attackers to modify configurations within PaperCut, enabling them to execute arbitrary code before authentication has even occurred on the affected servers.

Recent research released by Blackpoint Cyber sheds light on the sophisticated infrastructure and operational tactics employed by the attackers. Their findings reveal the utilization of AI-assisted tools to streamline the development, testing, and execution of exploits against hundreds of targets. This marks an evolution in cybercriminal methods where artificial intelligence plays a significant role in orchestrating attacks.

CVE-2026-81578 is characterized as an improper access control vulnerability, facilitating unauthorized access to modify critical PaperCut settings. The second vulnerability, CVE-2026-82078, relates to unsafe dynamic class loading, which allows for the execution of arbitrary Java bytecode when integrated settings are tampered with. Subsequent investigations by PaperCut disclosed that the attackers leveraged a combination of authentication bypass mechanisms, database driver behaviors, and dynamic class loading to execute malicious code successfully.

Blackpoint’s Adversary Pursuit Group identified an AI-enhanced workflow that included vulnerability research, exploit creation, and systematic retries, all while tracking progress through timestamped state files. The automated nature of certain processes allowed the attackers to manage and execute tasks with remarkable efficiency, filtering target lists by geographic location and employing scripts that utilized multiple workers to probe PaperCut servers.

Furthermore, the research uncovered two cutting-edge tools within the attackers’ environment: Hindsight, an AI-powered persistent memory resource, and AionUI, an interface designed for agent orchestration. While the findings indicate that AI did not independently discover the vulnerabilities or execute attacks devoid of human oversight, they reflect the manner in which AI tools can amplify operational capabilities and reduce the workload associated with these campaigns.

GreyNoise has separately reported that the campaign successfully compromised at least 440 instances of PaperCut NG/MF across 395 organizations spanning 48 countries. The research highlights the attendance of AI agents, which operated through OpenAI’s Codex framework, working in conjunction with a DeepSeek model to develop, test, and implement the exploits against vulnerable targets.

Historically, PaperCut has been a repeated target for adversarial actors, with documented incidents involving state-sponsored hacking groups and ransomware outfits exploiting prior authentication bypass vulnerabilities. The recent activity involving AI-driven tools underscores a significant shift in how attackers connect vulnerability research, exploitation, and failure analysis within scalable workflows.

Organizations operating internet-facing PaperCut NG/MF Application Servers are strongly urged to implement the latest emergency patches. PaperCut has explicitly recommended the installation of Emergency Patch Release 3, advising that this measure is essential even if previous updates have already been applied.

In consideration of the tactics observed in this campaign, potential MITRE ATT&CK techniques such as initial access, privilege escalation through exploitation of vulnerabilities, and evasion techniques through manipulation of application settings have likely come into play, magnifying the criticality for businesses to enhance their cybersecurity stances against evolving threats.

Source