AI Agents Compromised 440 PaperCut Servers, Researchers Say
A threat intelligence firm s 2026-9-10 18:39:5 Author: thecyberexpress.com(查看原文) 阅读量:3 收藏

PaperCut, PaperCut Compromise

A threat intelligence firm says it watched a Russian-speaking attacker turn hundreds of AI agents loose on a print management platform and compromise 440 servers in 48 countries — including 11 organizations in 26 seconds. It is the most vivid account yet of an autonomous intrusion campaign. It is also, so far, a single-source story that the vendor at the center of it has pointedly declined to endorse.

GreyNoise published the report on Sept. 9, describing a campaign it says launched Aug. 31 against PaperCut NG and MF, the self-hosted Java print management software used by a frequently cited 100 million people. The firm says it observed the operation through its own sensor network rather than reconstructing it from victim forensics after the fact.

GreyNoise counts 440 compromised instances across 395 organizations, with education absorbing 204 of them, and domain administrator privileges reached at 12 victims. It says the operator went from an empty workspace to remote code execution against a real victim in under four hours, and to harvested domain admin credentials in roughly six. One US high school, the report says, went from initial access to full domain admin in seven minutes. The agents ran on an OpenAI Codex harness alongside a DeepSeek model.

The most quietly alarming detail is not the speed. GreyNoise says the operator maintained a list of 28 countries the agents were told to leave alone — Russia, China, Iran and Venezuela among them — and that the victim data shows the agents hit some of them anyway. An attacker’s sanctions-avoidance policy failed because the automation did not respect it. The report frames this as evidence that unconstrained agentic operations drift, and that the drift is a risk to the attacker as much as to anyone else.

The underlying vulnerabilities are real and the exploitation is not in dispute. CVE-2026-81578, an authentication bypass, and CVE-2026-82078, an unsafe-reflection remote code execution flaw, were published Aug. 28 and can be chained. PaperCut shipped emergency patches on Aug. 28 and Sept. 1 and full maintenance releases — 26.0.5, 25.0.13 and 24.1.10 — on Sept. 10. CISA added both to its Known Exploited Vulnerabilities catalog on Aug. 31 with a Sept. 14 remediation deadline, a listing that predates the GreyNoise report and was driven by the earlier exploitation wave documented.

Read: PaperCut Issues Second Emergency Patch as Researchers Break Fix for Exploited Zero-Days

文章来源: https://thecyberexpress.com/ai-agents-compromised-440-papercut-servers/
如有侵权请联系:admin#unsafe.sh