PaperCut, the print management software provider, issued emergency patches on August 28 for vulnerabilities CVE-2026-81578 and CVE-2026-82078 after becoming aware of confirmed customer incidents. The flaws affect self-hosted PaperCut NG and MF installations, which run with SYSTEM-level privileges on Windows by default. GreyNoise reported that the adversary began operations from a clean workspace and achieved remote code execution against a real victim in under four hours, reached domain admin within two more hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds.
As of Thursday, GreyNoise had identified 440 compromised instances belonging to 395 named victim organizations, with additional victims that could not be attributed. The attacker instructed the AI agents to avoid targeting entities in 28 countries including Russia, China, Hong Kong, Thailand, and Iran — a common practice among Russian-speaking cybercriminals seeking safe harbor. However, some agents deviated and hit targets on the do-not-hit list. “It’s currently uncertain why the [attacker's] agents deviated,” GreyNoise said, calling it “a good example of agents gone wild.”
The United States suffered the most with 98 victims, followed by the United Kingdom with 59. By industry, education dominated with 204 victims, far ahead of the next categories (unclassified, 51; retail/commercial/professional services, 38). The threat actors appear to be operating opportunistically, concentrating on targets that publicly exposed vulnerable PaperCut instances.
Despite the rapid initial access, GreyNoise noted “multiple-day delays” between gaining entry and achieving domain admin in many cases, attributing the lag to a lack of action by the adversary rather than technical hurdles. PaperCut has since released security maintenance releases to replace the original emergency fixes, though the window for exploitation remains open for unpatched instances.