Critical

AI-powered attack exploited PaperCut flaws to hack 395 organizations

BleepingComputer
Actively Exploited

Overview

A recent cybersecurity incident has revealed that a group of likely Russian-speaking attackers exploited vulnerabilities in PaperCut NG/MF servers to compromise 395 organizations worldwide. Using a network of AI agents, they launched a sophisticated campaign that took advantage of unpatched flaws in these widely used print management solutions. The attackers targeted these servers, which are commonly found in businesses and educational institutions, making the breach particularly concerning for sensitive data exposure. Organizations using PaperCut products should urgently assess their systems for vulnerabilities and apply necessary security updates to protect against potential exploitation. This incident underscores the need for robust security practices, especially for software that handles critical operational functions.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: PaperCut NG, PaperCut MF
  • Action Required: Organizations should apply the latest security patches provided by PaperCut and review their configurations to mitigate risks associated with these vulnerabilities.
  • Timeline: Newly disclosed

Original Article Summary

A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]

Impact

PaperCut NG, PaperCut MF

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should apply the latest security patches provided by PaperCut and review their configurations to mitigate risks associated with these vulnerabilities.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Vulnerability, Data Breach, Critical.

Related Coverage

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

SecurityWeek

Anthropic has reported that Russian hackers are targeting AI companies to exploit their technology for malicious purposes. In a recent incident, these attackers used the Claude AI model to automate their malware evasion techniques, which helped them evade detection while carrying out their operations. This breach highlights a concerning trend where cybercriminals are not only stealing intellectual property, like a pre-release Claude model, but also misusing advanced AI tools to enhance their cyberattacks. The implications are significant, as it raises questions about the security of AI systems and the potential for their misuse in future attacks. Companies in the tech sector need to bolster their defenses against such tactics to protect their infrastructure and intellectual property.

Sep 11, 2026

PaperCut Flaws Exploited in AI-Powered Attacks

SecurityWeek

A Russian hacker group has harnessed artificial intelligence to exploit vulnerabilities in PaperCut software, impacting hundreds of organizations around the globe. These attacks involve creating and deploying sophisticated exploits that take advantage of specific flaws in the software. PaperCut is widely used for print management, making many businesses vulnerable to these AI-driven attacks. The implications are serious, as compromised systems can lead to unauthorized access to sensitive data and disruption of services. Companies using PaperCut should take immediate action to patch their systems and protect against these evolving threats.

Sep 11, 2026

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

The Hacker News

Attackers have exploited two vulnerabilities in JFrog Artifactory, a tool used to manage software packages for build pipelines, to gain admin access to self-hosted servers. This allowed them to install backdoors, enabling ongoing access and control. The attacks were observed between August 15 and September 8, but JFrog had already patched the vulnerabilities prior to the attacks. Therefore, only those servers that had not yet been updated were at risk. This incident underscores the importance of timely software updates, as failure to do so can leave systems vulnerable to exploitation by malicious actors. Organizations using JFrog Artifactory should ensure they are running the latest version to protect against these types of attacks.

Sep 11, 2026

Conti ransomware gang member sentenced to 4 years in prison

BleepingComputer

A Ukrainian man has been sentenced to four years in prison for his involvement with the Conti ransomware gang, which executed a series of attacks from 2021 to 2022. This gang was notorious for targeting businesses and organizations, demanding hefty ransoms in exchange for decrypting stolen data. The individual, whose exact role was not detailed, is part of a broader crackdown on cybercriminals involved in such ransomware schemes. The sentencing serves as a warning to others in the cybercrime community and aims to deter future ransomware activities. As ransomware attacks continue to plague organizations worldwide, this case highlights the ongoing efforts by law enforcement to hold perpetrators accountable.

Sep 11, 2026

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

The Hacker News

PaperCut has released a new security maintenance update to address two significant vulnerabilities in its software that were being actively exploited. The updates are available for users of PaperCut NG/MF versions 26.0.5, 25.0.13, and 24.1.10. This move replaces earlier emergency patches that were initially issued to tackle these issues. It's crucial for users running these versions to apply the updates promptly to protect their systems from potential attacks. The vulnerabilities pose risks to the security of printing services and could allow unauthorized access or manipulation of sensitive information.

Sep 11, 2026

Indonesia Hit by Android Banking App-Cloning Campaign

darkreading

Indonesia is facing a cybersecurity threat from a group known as GoldFactory, which is using a technique involving the Android Work Profile feature to distribute the Gigabud Trojan. This malicious software targets Android banking apps, allowing attackers to steal sensitive financial information from users. Another group, Mantax Otax, is reportedly spreading malware independently. This situation raises concerns for Android users in Indonesia, particularly those who rely on banking apps for financial transactions. The ability of these groups to exploit legitimate features in Android underscores the need for heightened vigilance among users and better security measures from app developers.

Sep 11, 2026