AI-Driven Automation Exploits PaperCut Flaws Across 395 Organizations

A large-scale automated campaign has compromised organizations by exploiting vulnerabilities in PaperCut NG/MF print management software. Cybersecurity researchers at GreyNoise and Blackpoint Cyber identified the activity, which leveraged automation to achieve a speed and scale that traditional manual exploitation cannot match.

The campaign specifically targeted vulnerabilities in the software. By chaining these flaws, the threat actor was able to gain initial access and, in at least one documented instance, move from the initial breach to full domain administrator privileges.

Mass Exploitation via Automation

The primary driver of the campaign’s success was the use of automated workflows. According to analysis from GreyNoise, these tools were tasked with automating the attack lifecycle, from exploit development to victim identification.

The attacker used automated systems to interface with Netlas.io API keys, generating lists of vulnerable targets worldwide. Once the full automation was launched, the campaign achieved staggering speed. Telemetry suggests the tools did not consistently adhere to geographic restrictions.

Abstract visualization of automated digital workflows and neural network paths.
The campaign leveraged AI agents to automate the entire attack lifecycle, from discovery to exploitation.

The education sector was among those affected by the campaign. This concentration is likely due to the widespread use of PaperCut software in schools and universities to manage campus printing services. Despite the sophisticated use of automation for the initial “break-in” phase, the attacker relied on conventional offensive tools for post-exploitation, including Mimikatz, Certipy, and BloodHound.

Technical Indicators and Mitigation

The Cybersecurity and Infrastructure Security Agency (CISA) added PaperCut vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 31, 2026. For federal agencies, the remediation deadline is set for September 14, 2026.

PaperCut released “Emergency Patch Release 3” on September 1, 2026. This update addresses both the original vulnerabilities and regressions found in previous security updates. Security teams are urged to verify their version of PaperCut NG/MF and update immediately to prevent further exploitation.

Research from Blackpoint Cyber identified malicious activity. Defenders should check for the presence of the aforementioned post-exploitation tools, as patching the software does not automatically remove an attacker who has already established a foothold within the network.

Evidence suggests a threat actor was behind the campaign, though the use of automated tools makes definitive attribution more complex. The speed of this campaign serves as a practical example of how automation can significantly shorten the “defender’s window”—the time between a vulnerability being discovered and it being exploited at a global scale.

More From Category

More Stories Today