Return to Threats

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

thehackernews.com 2026-09-10 AI agent abuse Critical

What Happened

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

Why It Matters

Report facts: The article describes a suspected Russian-speaking threat actor using hundreds of AI agents to systematically generate and refine exploits against newly disclosed PaperCut NG/MF vulnerabilities, compromising more than 440 instances according to Blackpoint Cyber and GreyNoise reports. The activity is tied to a specific IP address used to orchestrate large-scale automated exploitation. RealGround analysis: This demonstrates how coordinated AI agents can drastically accelerate exploit development and scanning against enterprise software, turning patch gaps into rapid mass compromise. Organizations should harden any AI-agent frameworks they use, continuously red-team agent behavior for abuse scenarios, and ensure business logic and access controls prevent agents from being repurposed for offensive exploitation at scale.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI agent abuse. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html

Talk to AI CISO