Executive Summary
In August 2026, a Russian-speaking threat actor orchestrated an unprecedented AI-powered exploitation campaign targeting PaperCut NG/MF servers worldwide. Using hundreds of AI agents powered by OpenAI's Codex and DeepSeek models, the attackers automated exploit development for CVE-2026-81578 and CVE-2026-82078, compromising 440 PaperCut instances across 395 organizations in 48 countries within days. The campaign demonstrated alarming speed, with attackers achieving remote code execution in under four hours and domain administrator privileges in just seven minutes at some targets, primarily affecting educational institutions.
This incident marks a critical inflection point in cybersecurity, showcasing how AI can compress traditional attack timelines from weeks to minutes. As threat actors increasingly weaponize AI for automated vulnerability discovery and exploitation, organizations face an unprecedented challenge where human-speed incident response becomes obsolete against machine-speed attacks.
Why This Matters Now
AI-powered attacks represent the new threat landscape reality, where attackers can achieve domain compromise in minutes rather than weeks. Organizations must urgently adopt AI-speed detection and response capabilities to defend against autonomous attack systems that operate faster than human analysts can respond.
Attack Path Analysis
AI-powered threat actors exploited PaperCut CVE-2026-81578 and CVE-2026-82078 to achieve RCE on vulnerable servers, then escalated to domain admin through credential dumping and pass-the-hash attacks. Attackers moved laterally across domain controllers using DCSync techniques to harvest complete NTDS.DIT databases. The campaign maintained C2 through tools like Ligolo-ng and exfiltrated domain credentials from 395 organizations across 48 countries. Full compromise occurred as quickly as 7 minutes in some cases, with the AI agents automating target discovery, exploit development, and credential harvesting at unprecedented scale.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
AI agents scanned internet using Netlas platform to identify vulnerable PaperCut NG/MF servers, then exploited CVE-2026-81578 and CVE-2026-82078 to achieve remote code execution within 4 hours of campaign start
Related CVEs
CVE-2023-27350
CVSS 9.8Improper access control vulnerability in PaperCut NG/MF allows unauthenticated attackers to execute arbitrary code with SYSTEM privileges via crafted requests to the user interface component.
Affected Products:
PaperCut Software International Pty Ltd PaperCut NG – < 22.0.9
PaperCut Software International Pty Ltd PaperCut MF – < 22.0.9
Exploit Status:
exploited in the wildCVE-2023-27351
CVSS 7.5Improper access control vulnerability in PaperCut NG/MF allows authenticated users to bypass authorization and gain elevated privileges through path traversal attacks.
Affected Products:
PaperCut Software International Pty Ltd PaperCut NG – < 20.1.7, 21.x < 21.2.11, 22.x < 22.0.9
PaperCut Software International Pty Ltd PaperCut MF – < 20.1.7, 21.x < 21.2.11, 22.x < 22.0.9
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
LSASS Memory
Pass the Hash
Group Policy Modification
Domain Account
Domain Account
Kerberoasting
PowerShell
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Privileged Access Management
Control ID: Identity-Advanced
PCI DSS 4.0 – Security Patch Management
Control ID: 6.3.2
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Higher Education/Acadamia
Education sector faced highest impact with AI-powered PaperCut exploitation affecting 50% of breaches, requiring immediate zero trust segmentation and egress security controls.
Government Administration
Critical infrastructure vulnerability to AI-enhanced attacks exploiting print management systems demands enhanced threat detection, anomaly response, and compliance with NIST frameworks.
Computer Software/Engineering
Software organizations using PaperCut systems face rapid AI-driven exploitation risks requiring multicloud visibility, Kubernetes security, and inline intrusion prevention capabilities.
Health Care / Life Sciences
Healthcare sector must address AI-powered lateral movement threats through encrypted traffic protection, microsegmentation, and HIPAA-compliant security controls for print infrastructure.
Sources
- AI-powered attack exploited PaperCut flaws to hack 395 organizationshttps://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations/Verified
- AI-orchestrated campaign against PaperCut NG/MFhttps://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mfVerified
- CISA Adds Two Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2023/04/19/cisa-adds-two-known-exploited-vulnerabilities-catalogVerified
- PaperCut Security Advisory - Critical Vulnerabilityhttps://www.papercut.com/kb/Main/PO-1216-and-PO-1219Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely limit the extensive lateral movement and domain-wide credential harvesting that enabled attackers to compromise 395 organizations through segmented network access and controlled east-west traffic flows.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security controls would likely constrain the scope of initial exploitation by limiting network reachability to vulnerable PaperCut servers through segmented access policies and workload isolation boundaries.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely limit privilege escalation scope by restricting access to domain controllers and constraining the ability to perform credential dumping across multiple systems simultaneously.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement by limiting authenticated access between network segments and reducing the effectiveness of pass-the-hash attacks across domain infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely constrain command and control operations by limiting tunneling capabilities and reducing the scope of coordinated attacks across multiple target organizations simultaneously.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain the massive credential exfiltration by limiting outbound data flows and reducing the volume of NTDS.DIT dumps that could be transmitted from compromised domain controllers.
The blast radius of potential ransomware or data theft operations would likely be constrained to isolated network segments rather than enabling domain-wide compromise across 395 organizations simultaneously.
Impact at a Glance
Affected Business Functions
- Print and Document Management Services
- Network Authentication Systems
- Administrative IT Operations
- Educational Technology Infrastructure
Estimated downtime: 7 days
Estimated loss: $2,500,000
Domain administrator credentials, NTDS.DIT database dumps containing user authentication hashes, LSASS memory contents with plaintext passwords, and registry secrets from 395 organizations across education, healthcare, and corporate sectors affecting approximately 280 credential sets.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to prevent lateral movement between compromised servers and domain controllers through identity-based microsegmentation policies
- • Deploy Egress Security & Policy Enforcement to block unauthorized data exfiltration and detect DCSync activities attempting to transfer large credential databases
- • Enable Multicloud Visibility & Control to detect anomalous AI-driven automation patterns and rapid multi-target exploitation campaigns
- • Activate Threat Detection & Anomaly Response capabilities to identify suspicious tools like Mimikatz, BloodHound, and credential dumping activities in real-time
- • Apply Inline IPS (Suricata) with updated signatures for CVE-2026-81578 and CVE-2026-82078 exploitation patterns to prevent initial compromise of vulnerable PaperCut servers



