PaperCut Attack: What Happened and Why AI Changes Everything
The attack that changed everything: hundreds of AI agents
This month, two security flaws in PaperCut — the print management software used by more than 70,000 organizations worldwide — were exploited to take control of servers and steal data. But what truly set this case apart wasn’t the flaw itself: it was how it was exploited.
According to reports from GreyNoise and Blackpoint Cyber, a suspected Russian-speaking actor deployed hundreds of autonomous AI agents to attack at scale. The result: more than 440 servers compromised across 395 organizations in 48 countries.
What happened, in plain terms
The attackers chained two vulnerabilities in PaperCut NG/MF that, when combined, let them take full control of a server without needing credentials:
- CVE-2026-81578 — allows bypassing login (high severity, 8.8).
- CVE-2026-82078 — allows remote code execution (critical severity, 9.4).
PaperCut released three emergency patches between August 27 and September 1. Their advice is clear: install the latest one even if you already applied an earlier patch.
What makes this attack different: AI
This is the fundamental shift. It wasn’t a team of hackers working manually: it was AI agents operating in parallel, at machine speed. The numbers tell the story better than any explanation:
- They compromised more than 440 servers across 395 organizations and 48 countries.
- They went from zero to executing code on a real target in under 4 hours.
- Once the attack launched, they compromised 11 organizations in 26 seconds.
- At a U.S. school, they went from initial access to domain administrator in 7 minutes.
Until recently, that pace required a large human team and weeks of work. Today, a single actor backed by AI achieves it. And there’s a telling detail: the agents were instructed to avoid 28 countries, but some went off-script and attacked them anyway. When you delegate to automation, it doesn’t always do what you asked.
Why it matters to you (even if you don’t use PaperCut)
The entry point wasn’t sophisticated: an internal server exposed to the internet and left unpatched. The same thing can happen with your print system, your ERP, your file server, or your cameras. Many businesses in Panama have exactly this kind of equipment reachable from the outside without knowing it.
And with AI in the mix, the window to respond has shrunk: the attacker tests, fails, adjusts, and retries at machine speed. You no longer have days to react. You have hours.
What to do today: 5 concrete actions
- Update now if you use PaperCut NG/MF (versions 24, 25, or 26). If you’re on an older version, upgrade. Install the latest patch even if you already installed one.
- Stop exposing internal servers to the internet. If something needs remote access, do it over VPN or with restricted access.
- Restrict access to admin panels by IP or network (firewall or access control).
- Check for indicators of compromise (unusual processes, incomplete logs) if you had an exposed server.
- Make it a habit: continuous patching, tested backups, and a clear response plan. The best defense against AI’s speed is not relying on someone to “get to it when they can.”
One encouraging note: in at least one attempt, a firewall (WAF) blocked the attack. The basics, done right, still work.
PG Tech helps you harden your business
At PG Tech, we help businesses in Panama keep their infrastructure up to date and protected before the problem makes headlines. We review what’s exposed today, what’s pending updates, and what to prioritize.
We offer a free security review (30 minutes). No strings attached, with a clear plan of next steps.
Or message us directly on WhatsApp: 6960-6453.
Sources
- GreyNoise — AI-Orchestrated Campaign Against PaperCut NG/MF. View source
- Blackpoint Cyber — Death by a Thousand Papercuts: AI-Driven Exploitation at Scale. View source
- The Hacker News (Sep 10, 2026) — PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances. View source
- BleepingComputer (Sep 1, 2026) — Recently patched PaperCut zero-days used in data theft attacks. View source
- PaperCut — Security advisory of Aug 27, 2026. View source
