AI Agents Exploit PaperCut Flaws in Global Breach

← Back to articles

AI Agents Exploit PaperCut Flaws in Global Breach

A new attack campaign used artificial‑intelligence agents to exploit vulnerabilities in PaperCut print‑management software, compromising at least 440 installations across 395 organizations in 48 countries. Researchers at GreyNoise traced the operation to a Russian‑speaking threat actor who first built a test environment with a vulnerable copy of PaperCut NG/MF and an Active Directory server, then let autonomous AI tools carry out the bulk of the intrusions.

The compromised organizations range from schools and hospitals to corporate offices that rely on PaperCut to control printing costs. The attackers leveraged known flaws in the software to gain unauthenticated access to the management console, allowing them to download credentials and move laterally within the network. By automating the exploitation with AI agents, the group could scale the attack quickly, targeting hundreds of sites without manual intervention for each breach.

GreyNoise reported that the AI agents performed most of the repetitive steps, such as scanning for vulnerable endpoints, injecting malicious payloads, and exfiltrating data. The use of machine‑learning tools does not change the underlying weakness: outdated or unpatched PaperCut versions remain open to exploitation. The campaign highlights how threat actors can combine existing software bugs with advanced automation to increase attack volume.

Users of PaperCut should verify that they run the latest patched version of the software. Administrators need to review access logs for any unusual activity, especially connections from unknown IP addresses to the PaperCut web interface. Disabling default credentials, enforcing strong password policies, and segmenting the print management server from the rest of the network can reduce the attack surface. Network monitoring tools such as the free intrusion‑detection scanner available on ComputerScams.com can help spot unauthorized access attempts.

In addition to patching, organizations should audit their Active Directory configurations for unnecessary privileges and ensure multi‑factor authentication is enabled for all administrative accounts. Regular backups of configuration files and logs will aid recovery if an intrusion is detected. Employees should be reminded that legitimate IT staff will never ask for passwords via email or instant message, a common tactic used after gaining footholds in a network.

The incident serves as a reminder that automation can amplify even modest vulnerabilities. Keeping software up to date, restricting access, and monitoring for anomalies remain the most reliable defenses against such AI‑assisted campaigns.

A practical step you can take right now is to check the version of PaperCut or any similar management software you use and apply the latest security updates immediately.

Source: Read the original report

Scroll to Top