What Happened
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to
Why It Matters
Report facts: The article describes a suspected Russian-speaking threat actor using hundreds of AI agents to systematically generate and refine exploits against newly disclosed PaperCut NG/MF vulnerabilities, compromising more than 440 instances according to Blackpoint Cyber and GreyNoise reports. The activity is tied to a specific IP address used to orchestrate large-scale automated exploitation. RealGround analysis: This demonstrates how coordinated AI agents can drastically accelerate exploit development and scanning against enterprise software, turning patch gaps into rapid mass compromise. Organizations should harden any AI-agent frameworks they use, continuously red-team agent behavior for abuse scenarios, and ensure business logic and access controls prevent agents from being repurposed for offensive exploitation at scale.
RealGround Analysis
This signal maps to AI agent abuse. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html
