PaperCut Attacks Escalate: AI Agents Hit 395 Organizations
A month after PaperCut's zero-days surfaced, GreyNoise reports that one attacker used hundreds of AI agents to compromise at least 440 PaperCut servers at 395 organizations, reaching domain-admin level at 12. Move to PaperCut 26.0.5, 25.0.13 or 24.1.10, upgrade version 23 or older, and check any previously exposed server for compromise.
Key takeaways
- GreyNoise reported that one attacker used hundreds of AI agents to compromise at least 440 PaperCut NG/MF instances at 395 organizations in 48 countries.
- The attacker went from an empty workspace to code execution on a real victim in under four hours and ultimately reached domain-admin level at 12 organizations.
- PaperCut's tested maintenance releases 26.0.5, 25.0.13 and 24.1.10 replace all of its emergency patches, while version 23 and earlier never received a fix.
- A public Metasploit module now implements the attack chain, so any unpatched PaperCut server reachable from the internet should be assumed to have been found.
- If your PaperCut server was exposed before you patched, check it for compromise and reset its credentials instead of assuming the patch solved everything.
When we covered the PaperCut zero-days on August 31, the advice was about patching fast. A month later, the story is about the servers that weren't patched fast enough. Researchers have documented a single attacker using hundreds of AI agents to break into PaperCut print-management servers worldwide, some of those break-ins reached domain-admin level on the victims' Windows networks, and ready-made exploit code is now public.
If your office runs PaperCut NG or MF, the question has shifted from "did we patch?" to "were we already found?"
What's changed since the PaperCut zero-days were disclosed?
Three things: the attacks were automated at scale, PaperCut replaced its emergency patches with fully tested releases, and exploit code went public. None of it changes the underlying flaws, CVE-2026-81578 and CVE-2026-82078, but all of it shortens the time an unpatched server can expect to go unnoticed.
The fixes came in stages. On September 1, PaperCut shipped a third emergency patch that repaired two things the earlier patches broke, SAML single sign-on and legacy Microsoft SQL Server drivers used for external card lookup, and closed off more attack vectors seen in the wild, according to PaperCut's advisory, Arctic Wolf and eSentire. Tested maintenance releases followed; more on those below.
How did one attacker reach 395 organizations so quickly?
By delegating the work to AI. In research published in early September, threat-intelligence firm GreyNoise reported that a likely Russian-speaking actor used AI to develop and test exploits for the two PaperCut flaws, then turned hundreds of AI agents loose on internet-exposed servers. The agents ran on OpenAI's Codex harness with a DeepSeek model plus public offensive-security tools, as The Hacker News and Help Net Security also reported.
The tally: at least 440 PaperCut NG/MF instances compromised, belonging to 395 identified organizations in 48 countries, according to GreyNoise, SecurityWeek and Dark Reading.
The speed is the part worth sitting with. GreyNoise says the attacker went from an empty workspace to remote code execution on a real victim in just under four hours, and to the first Active Directory domain admin two hours after that. Once the full campaign was running, it compromised at least 11 organizations in 26 seconds, figures Dark Reading and Help Net Security also cite.
Twenty-six seconds is less time than it takes to find your copier dealer's phone number. The comfortable assumption that small offices have weeks before anyone gets around to them doesn't hold when the "anyone" is software running around the clock.
Who was hit hardest, and does that include small businesses?
Education, by a wide margin, though GreyNoise doesn't think the attackers were picking sectors. It counted 204 victim organizations in education, heavily concentrated in the United States, and attributes that to PaperCut's customer base rather than deliberate targeting, as Help Net Security and The Register reported.
That attribution is the useful part for a business owner. The campaign went wherever exposed PaperCut servers were. A law office, clinic or accounting firm with an unpatched, internet-reachable server was in the same pool as a school district, often with fewer IT staff to notice.
Why is a hacked print server now a whole-network problem?
Because the attackers didn't stop at the print server. According to GreyNoise, BleepingComputer and The Hacker News, they harvested credentials from compromised servers and pushed into Windows Active Directory, reaching domain-admin level at 12 organizations.
In plain terms: a print server joined to your Windows domain can hold reusable credentials in memory. Steal those, try them against the server that controls every account in the office, and you may end up controlling the whole network, not just the printers. Twelve out of 395 is a small fraction, but those twelve handed an attacker the keys to their whole domain.
Printers and print servers leaking Windows credentials isn't new; our explainer on pass-back attacks shows another route. What's new is the scale and the speed.
Which PaperCut version should you be running now?
A maintenance release, not an emergency patch. PaperCut has shipped fully QA-tested NG/MF releases 26.0.5, 25.0.13 and 24.1.10, which include every fix from Emergency Patch Releases 1 through 3 plus extra hardening, and it advises customers still running an emergency-patch build to move to one, according to PaperCut's 26.0 release history, The Hacker News and Arctic Wolf.
| Your PaperCut NG/MF version | What to do |
|---|---|
| 26.x | Move to 26.0.5 or later |
| 25.x | Move to 25.0.13 or later |
| 24.x | Move to 24.1.10 or later |
| 23 or earlier | No fix exists: upgrade to the 24, 25 or 26 line, or retire the server |
| Any emergency-patch build | Replace it with the maintenance release for your line |
One practical snag: if your setup looks up users' cards or ID badges in an external database, PaperCut says that configuration must be reconfigured after upgrading. Ask whoever installed it to plan for that, so badge release doesn't stop working on upgrade day.
The version-23 row isn't a formality. PaperCut never issued emergency patches or maintenance releases for version 23 or earlier, as its advisory, Huntress and the Canadian Centre for Cyber Security all note.
Waiting is also riskier than it was in August. A Metasploit module from Rapid7 now implements the unauthenticated two-flaw chain against PaperCut 24.x, 25.x and 26.x, according to Rapid7, the Metasploit project and GBHackers, and Arctic Wolf notes that public exploit code is available. That puts the attack in off-the-shelf tools, so an unpatched server no longer needs a sophisticated attacker to find it.
What this means for San Fernando Valley offices
For a Valley office, the real question isn't only "are we patched?" It's "could anyone reach our PaperCut admin page from the internet between late August and the day we patched?" If the answer is yes, or "we don't know," treat the server as possibly compromised, not just out of date. A patch locks the door; it doesn't check whether someone is already inside.
That has a legal edge in California. Our August post explained SB 446's 30-day deadline for notifying affected Californians after discovering a breach of their personal information. The same law adds a second clock worth knowing: if more than 500 Californians are notified, a sample copy of the notice must go to the state Attorney General within 15 calendar days of notifying them, according to the bill text, The National Law Review and JD Supra. Because the 30 days run from discovery, a prompt, professional check of an exposed server beats months of not knowing.
If you run a private school, tutoring center or training program anywhere from Chatsworth to Studio City, the education numbers are a direct warning. If you run a law, medical or accounting office, the lesson is that attackers went wherever PaperCut was. Either way, check what your cyber insurance policy requires you to report, and when.
What to do now
- Confirm your exact version. Ask your copier dealer or IT provider for the PaperCut NG/MF version number and compare it with the table above.
- Get off emergency patches. Move to 26.0.5, 25.0.13 or 24.1.10 or later, and plan the external-database card lookup reconfiguration if you use it.
- Upgrade or retire version 23 and older. There's no fix for those versions.
- Keep the admin interface limited to trusted internal IP addresses. PaperCut's first piece of advice still applies after patching.
- Hunt for signs of an earlier break-in. Check for PaperCut's published indicators, including a "Remote Access Service" running SimpleHelp's SimpleService.exe and unexpected AnyDesk installs, plus administrator or Domain Admin accounts nobody remembers creating.
- Reset credentials if the server was exposed. Change the PaperCut service account password, any directory or database credentials stored in PaperCut, and domain admin passwords.
- Don't run PaperCut on a domain controller or under a domain-admin account. Give it only the access it needs.
- Bring in counsel and your insurer early if you find evidence of compromise.
Not sure which version you're on, or whether your print server was ever exposed? Book a free virtual consultation and we'll help you get a straight answer from your dealer and a plan sized for a small office.
Frequently asked questions
- Which PaperCut versions fix CVE-2026-81578 and CVE-2026-82078?
- PaperCut's fully tested maintenance releases 26.0.5, 25.0.13 and 24.1.10 include every fix from its three emergency patches plus extra hardening, and PaperCut advises emergency-patch users to move to them. Versions 23 and earlier received no fix at all, so those servers must be upgraded to the 24, 25 or 26 line.
- How did AI agents attack PaperCut servers?
- GreyNoise reported that a likely Russian-speaking actor used AI to build and test exploits, then deployed hundreds of AI agents running on OpenAI's Codex harness with a DeepSeek model. The campaign compromised at least 440 PaperCut NG/MF instances at 395 organizations in 48 countries and, once the full campaign launched, at least 11 organizations in 26 seconds.
- Is a patched PaperCut server safe?
- Not necessarily. Patching blocks new attacks through these flaws but doesn't remove attackers who got in earlier. If your PaperCut admin page was reachable from the internet before you patched, check for signs of compromise, such as unexpected remote-access tools or new admin accounts, and reset credentials stored on or used by the server.
- Why would attackers target a print server?
- A print server joined to a Windows domain can be a stepping stone to the whole network. In the PaperCut campaign, attackers harvested credentials from compromised servers, pushed into Windows Active Directory and reached domain-admin level at 12 organizations, according to GreyNoise and several security news outlets.
Sources
Fact-checked : figures and claims in this article were cross-checked against at least three independent published sources. Where a vendor's own documentation is the only authoritative source, the article attributes the claim to that vendor. The main sources are listed below.
- Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF — GreyNoise
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances — The Hacker News, 2026-09
- AI agents exploited PaperCut flaws to breach 395 organizations — Help Net Security, 2026-09-11
- PaperCut Flaws Exploited in AI-Powered Attacks — SecurityWeek
- PaperCut AI swarm attack and the cyber kill chain — Dark Reading
- Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script — The Register, 2026-09-10
- AI-powered attack exploited PaperCut flaws to hack 395 organizations — BleepingComputer
- URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) — PaperCut, 2026-08-27
- CVE-2026-81578 and CVE-2026-82078: PaperCut NG/MF vulnerabilities — Arctic Wolf
- PaperCut discloses zero-day vulnerabilities CVE-2026-82078 and CVE-2026-81578 — eSentire
- PaperCut NG/MF 26.0 release history — PaperCut
- PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws — The Hacker News, 2026-09
- PaperCut NG/MF actively exploited — Huntress
- PaperCut security advisory (AV26-858) — Canadian Centre for Cyber Security, 2026-08-28
- Metasploit Wrap Up: This One Goes to Sixteen! — Rapid7
- Add exploit module for the recent PaperCut MF/NG 0day (CVE-2026-81578 + CVE-2026-82078) — Rapid7 Metasploit Framework (GitHub)
- Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities — GBHackers
- Attackers plant remote access tools on compromised PaperCut servers — Help Net Security, 2026-08-31
- PaperCut Exploitation Escalates to Active Intrusions — SecurityWeek
- SB 446 bill text and status (Chapter 319, Statutes of 2025) — California Legislative Information, 2025-10-03
- 30 Day Deadline for Data Breach Notifications Set in California — The National Law Review
- Prepare for California's 2026 Data Breach Law's Notice Requirement — JD Supra
About Valley Printer Pros Team
Our team of printer industry experts brings decades of experience helping small businesses optimize their printing operations. We provide unbiased advice and practical solutions that save money and improve productivity.
Get Expert AdviceServing San Fernando Valley Businesses
We provide on-site printer consulting, setup, and lease escape support across the Valley:
Related Articles
On September 17, HP Wolf Security reported phishing emails with PDF "invoices" blurred behind a QR code that tells staff to scan it with their phone, leading to a fake Microsoft sign-in page. Tell accounts-payable staff never to scan QR codes in unexpected invoices, verify invoices by phone, and protect Microsoft 365 with MFA.
Microsoft's September 8, 2026 Patch Tuesday fixed a Critical (CVSS 9.8) Windows HTTP Print Provider flaw, CVE-2026-69769, that needs no sign-in or click, plus Print Spooler privilege bugs. None were exploited, and the month's zero-days weren't print-related. Test the September cumulative update on one PC, then install it everywhere.
On August 27, PaperCut warned that attackers were exploiting flaws in its NG and MF print-management software, and on August 31 CISA listed both chained bugs as actively exploited. Ask your copier dealer whether you run PaperCut, restrict its admin page to trusted addresses, patch versions 24 to 26, and upgrade anything older.
Need Help with Your Printer Decisions?
Don't navigate printer purchases, leases, or problems alone. Our experts provide unbiased advice tailored to your specific business needs.