Hackers Use Hundreds of AI Agents to Exploit PaperCut Zero-Days

Hackers Use Hundreds of AI Agents to Exploit PaperCut Zero-Days

Blackpoint Cyber and GreyNoise detail attacks exploiting two PaperCut zero-days, with hundreds of AI agents used to compromise servers across 48 countries.

Listen to this article

0:00

Press play to start listening

Cybersecurity researchers at Blackpoint Cyber and GreyNoise have identified an active cyberattack campaign targeting PaperCut NG and PaperCut MF, self-hosted print management software used for printing, copying, and scanning. The attacks target the products’ Application Servers and exploit CVE-2026-81578 and CVE-2026-82078.

Hackread.com previously reported that PaperCut NG/MF Application Servers were being actively attacked and that the vendor had released emergency patches for the two zero-day vulnerabilities. The flaws can be chained to modify PaperCut configuration and achieve pre-authentication remote code execution on affected servers.

New research from Blackpoint Cyber, shared with Hackread.com, provides a closer look at the infrastructure and workflow behind exploitation of the same vulnerabilities, showing how AI-assisted tooling was used to develop, troubleshoot, and scale attacks across hundreds of targets.

How the AI Attack Pipeline Worked

CVE-2026-81578 is an improper access control flaw that can allow unauthenticated attackers to modify certain PaperCut settings. CVE-2026-82078 involves unsafe dynamic class loading that can allow arbitrary Java bytecode residing on the application classpath to execute when those settings are manipulated.

PaperCut later said its investigation found that the attack combined the authentication bypass with database-driver behaviour, arbitrary file-writing capabilities, and Java class loading to achieve code execution.

Blackpoint’s Adversary Pursuit Group (APG) identified an AI-assisted workflow covering vulnerability research, exploit development, target selection, troubleshooting, and repeated retries. Timestamped state files tracked completed tasks, blockers, failures, code changes, target counts, and next steps. According to Blackpoint, the tooling also automated several parts of the campaign:

  • Target lists were filtered by country, including 28 countries listed for exclusion.
  • Scripts used up to 80 workers to check PaperCut servers over HTTP and HTTPS before heavier processing.
  • Separate tools generated retry lists based on specific failure types.
  • A campaign runner was configured for up to 200 concurrent targets and as many as 100 retry rounds.

Blackpoint also found Hindsight, an AI persistent-memory layer, and AionUI, an agent orchestration interface, in the broader operator environment. The findings do not show AI independently discovering a zero-day or compromising targets without human involvement, but demonstrate how AI assistance reduced the effort needed to operate the campaign at scale.

GreyNoise separately reported that the campaign compromised at least 440 PaperCut NG/MF instances across 395 organizations in 48 countries. Its research also found that the attackers used hundreds of AI agents running through OpenAI’s Codex harness, alongside a DeepSeek model, to develop, test, and deploy the exploits.

AI assisted campaign feedback loop (Source: Blackpoint Cyber)

PaperCut Exploitation Has a History

PaperCut has been targeted before. As Hackread.com reported in 2023, attackers including Iranian state-sponsored hacking groups Mango Sandstorm and Mint Sandstorm, and other groups like Cl0p and LockBit exploited CVE-2023-27350, an authentication-bypass vulnerability that could lead to remote code execution on vulnerable PaperCut NG/MF servers.

The latest activity shows how AI-assisted tooling can connect vulnerability research, exploitation, failure analysis, and repeated targeting into a scalable workflow.

Organizations running internet-facing PaperCut NG/MF Application Servers should install the latest emergency patch. PaperCut recommends installing Emergency Patch Release 3 even on systems where an earlier emergency patch has already been applied.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts