Key Facts
GreyNoise reports that a likely Russian-speaking actor used AI-assisted workflows to develop and use exploits for PaperCut NG/MF CVE-2026-81578 and CVE-2026-82078. It says the campaign compromised at least 440 PaperCut instances at 395 identified organizations in 48 countries.
Technical Details
GreyNoise says the actor used an OpenAI Codex harness, a DeepSeek model, and publicly available offensive tools after testing against a lab environment. It reports that the actor used the two PaperCut vulnerabilities to obtain access and, in some cases, domain-administrator privileges.
Impact & Mitigation
GreyNoise reports credential harvesting and domain-administrator access in a subset of victims. Apply PaperCut’s emergency security updates for the affected vulnerabilities immediately, review internet exposure of PaperCut servers, and investigate for compromise using the vendor and GreyNoise guidance.
