PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Summary
A suspected Russian-speaking attacker used hundreds of AI agents (powered by OpenAI Codex and DeepSeek models) to exploit two security flaws in PaperCut NG/MF software, compromising over 440 instances across 395 organizations in 48 countries, primarily targeting the education sector. The attacker combined AI-driven exploit development with offensive security tools to gain remote access and harvest credentials, sometimes achieving full administrative control in just minutes. The attacker's ultimate goals remain unclear, though the activity suggests either initial-access development or preparation for data theft or ransomware attacks.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html
First tracked: September 10, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 92%