system: OPERATIONAL
← back to all hacks
AGENTS CRITICAL NEW

AI agents ran a mass-exploitation campaign against 440 PaperCut servers

Blackpoint and GreyNoise document an attacker who used hundreds of AI agents to go from empty workspace to remote code execution in under four hours against PaperCut NG/MF.

2026-09-29 // 5 min affects: papercut-ng, papercut-mf, openai-codex, deepseek

What is this?

On September 9, 2026, Blackpoint Cyber and GreyNoise each published analyses of a campaign against PaperCut NG/MF print-management servers. The Hacker News summarized both on September 10. According to the researchers, a suspected Russian-speaking actor used “hundreds of AI Agents” built on OpenAI Codex and a DeepSeek model to handle vulnerability research, tooling, target selection and campaign execution. At least 440 instances across 395 organizations in 48 countries were compromised, mostly in education.

The underlying flaws, an authentication bypass and an unsafe-reflection code-execution bug, were disclosed and patched by the vendor on August 28, 2026. The novelty is not the bugs but the speed and automation of the exploitation.

How it works

Blackpoint recovered state files from exposed operator infrastructure. They show AI assistance across the whole lifecycle: patch comparison and research (starting August 31), proof-of-concept development, target sourcing, campaign execution, failure analysis and repeated retry waves. A campaign runner processed 517 targets in its first pass, drew on a master list of 4,107 IP addresses, and was configured for up to 100 retry rounds. Failures (291 in one snapshot) were sorted into six categories rather than retried blindly, and agents kept checkpoint notes recording completed work, blockers and next hypotheses.

GreyNoise reports the actor progressed “from an empty workspace to first achieving RCE against a real victim in just under four hours,” compromised at least 11 organizations in 26 seconds during the active phase, and took one school from initial access to domain administrator in seven minutes. This article deliberately omits exploit specifics; the vendor advisory and the two research posts cover the defender-relevant detail.

Example prompt

A defensive prompt to hand your agent when a vendor bulletin lands. It checks version, exposure and behavioral signs of compromise without touching the system; any exploit detail is redacted, since what matters is what to look for.

# Defensive check — triage a PaperCut NG/MF server after a new security bulletin
Report, read-only:
  - installed version and whether it is a fixed release or version 23 or older
  - whether the application server is reachable from the public internet
  - any child process of the PaperCut server (cmd.exe, PowerShell, discovery tools)
  - unexpected class files under the server library directory
  - recent changes to user-lookup database driver / URL settings: [REDACTED]
Do not patch, restart, delete or run anything. Output the findings table only.

Why it matters

The gap between patch release and mass exploitation is the number defenders live by, and this campaign compresses it. A patch diff, once a task for a skilled human, becomes an input to an agent loop that iterates until something works. Self-hosted, internet-exposed, SYSTEM-privileged Java applications like PaperCut are exactly the shape of target where that pays off. Huntress noted roughly 47% of the ~2,500 installations it tracks ran version 23 or older, which receives no patch.

There is also a counterpoint from GreyNoise: in at least one case a conventional web application firewall stopped the adversary. AI-assisted attackers still hit ordinary controls.

Defenses

  • Patch on a timeline of hours for internet-facing systems. Assume any security bulletin can be weaponized the same day. Apply the fixed releases (26.0.5, 25.0.13, 24.1.10 per Huntress) and migrate off unsupported version 23.
  • Remove public exposure. Restrict the PaperCut application server to trusted IP ranges, a VPN or private paths.
  • Hunt on behavior, not indicators. Look for the PaperCut server process spawning cmd.exe, PowerShell or discovery tools, unexpected class files under the server library directory, and unexpected changes to user-lookup database driver and URL settings.
  • Put a WAF in front of legacy services as a compensating control while patching.
  • Preserve forensic evidence before patching any system that was exposed during August 26 to September.
  • Plan for the first patch being incomplete. The first emergency fix was bypassed and a second was issued the same day; re-verify you are on the latest build.

Status

ItemDetail
Vendor bulletin2026-08-27/28, PaperCut
Research published2026-09-09, Blackpoint Cyber and GreyNoise
Fixed releases26.0.5, 25.0.13, 24.1.10 (per Huntress)
Unpatched lineVersion 23 and older
ReferencesCVE-2026-81578 (authentication bypass), CVE-2026-82078 (code execution)

Sources