HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

AI Agents Exploit PaperCut Vulnerabilities, Compromise 395 Organizations Across 48 Countries

A threat actor used large‑language‑model agents to automate attacks against unpatched PaperCut NG/MF servers, compromising 395 organizations and harvesting domain‑admin credentials. The incident underscores the importance of continuous access‑control assurance and rapid patch deployment for audit readiness.

Verisq™ Intelligence · 📅 September 11, 2026 · 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
4 recommended
📰
Source
databreachtoday.com

AI Agents Exploit PaperCut Vulnerabilities, Compromise 395 Organizations Across 48 Countries

What Happened – A Russian‑speaking threat actor leveraged large‑language‑model agents to automate exploitation of two newly disclosed PaperCut NG/MF flaws (an authentication bypass and a remote‑code‑execution bug). The campaign hit 395 organizations in 48 countries, compromising at least 440 PaperCut servers and obtaining domain‑administrator credentials in 12 cases.

Why It Matters for Trust & Control Assurance

  • Demonstrates how unpatched authentication and execution flaws can be weaponised at scale, overwhelming manual patch‑management processes.
  • Highlights the need for continuous verification that access‑control mechanisms (least‑privilege, multi‑factor) are enforced and auditable after a vulnerability is disclosed.
  • Shows the value of real‑time evidence collection (log aggregation, privileged‑access monitoring) to prove due‑diligence during an audit.

Who Is Affected – Primarily education institutions (≈ 204 victims), but also health, government, and private‑sector organizations that run self‑hosted PaperCut installations.

Recommended Actions

  1. Deploy PaperCut’s September 10 emergency patches immediately on all on‑premise instances.
  2. Verify that privileged accounts are protected by MFA and that default or overly‑privileged service accounts are removed or constrained.
  3. Enable centralized logging of PaperCut and Active Directory events; correlate with threat‑intel feeds for AI‑driven exploit patterns.
  4. Conduct a rapid control‑assurance review of your access‑control policies and capture evidence for audit readiness.

Technical Notes – The attack chain leveraged:

  • Vulnerability 1: authentication bypass (CVE‑2025‑XXXX, CVSS 9.8).
  • Vulnerability 2: remote‑code execution (CVE‑2025‑YYYY, CVSS 9.3).
  • AI agents built on OpenAI Codex and DeepSeek models to generate and execute exploit code at scale.
  • Post‑exploitation steps included credential dumping and lateral movement to Windows domains.

Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/ai-agents-used-in-papercut-attacks-on-395-organizations-a-32801

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →