Key Facts

GreyNoise reports that a likely Russian-speaking actor used AI-assisted workflows to develop and use exploits for PaperCut NG/MF CVE-2026-81578 and CVE-2026-82078. It says the campaign compromised at least 440 PaperCut instances at 395 identified organizations in 48 countries.

Technical Details

GreyNoise says the actor used an OpenAI Codex harness, a DeepSeek model, and publicly available offensive tools after testing against a lab environment. It reports that the actor used the two PaperCut vulnerabilities to obtain access and, in some cases, domain-administrator privileges.

Impact & Mitigation

GreyNoise reports credential harvesting and domain-administrator access in a subset of victims. Apply PaperCut’s emergency security updates for the affected vulnerabilities immediately, review internet exposure of PaperCut servers, and investigate for compromise using the vendor and GreyNoise guidance.

Sources

By Allan