A likely Russian-speaking malicious cyber actor leveraged artificial intelligence to orchestrate a global campaign exploiting PaperCut NG/MF print management software via CVE-2026-81578 and CVE-2026-82078. Using AI agents powered by DeepSeek models and OpenAI's Codex, the adversary moved from empty workspace to first remote code execution in under four hours, compromising at least 440 PaperCut instances across 395 organizations in 48 countries. The campaign originated from IP 45.142.193.132, which had been tracked since July 2026 for attacks against various technologies. The adversary developed and tested exploits in a self-hosted lab environment before launching coordinated attacks using AI agents to achieve rapid compromise, with the fastest domain admin access achieved in just five minutes. Domain administrator access was confirmed in 12 organizations, primarily affecting educational institutions in the United States.
Created: 2026-09-10
Indicatorsは見つかっていない。
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。