Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Hundreds of AI bots exploited PaperCut flaws, breaching over 395 organizations worldwide

A threat actor deployed dozens of AI agents to leverage two newly disclosed PaperCut vulnerabilities, gaining access to at least 395 victims, primarily in the U.S. education sector.

GreyNoise reports that an unidentified, likely Russian-speaking criminal unleashed hundreds of AI agents powered by OpenAI’s Codex and a DeepSeek model to weaponize two PaperCut MF/NG bugs disclosed days earlier. The bots achieved remote code execution and credential theft, allowing rapid privilege escalation; one U.S. high school moved from initial foothold to domain admin in seven minutes. PaperCut issued emergency patches for CVE-2026-81578 and CVE-2026-82078 on August 28 and later replaced them with maintenance releases, yet at least 395 organizations in 48 countries—mostly schools—had been compromised.

The attacker programmed the agents to spare entities in 28 countries, including Russia and China, but some bots still hit targets on the exclusion list. The operation originated from IP 45.142.193.132, a address previously linked to attacks on Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox VE. Cloudflare’s WAF blocked one attempt, underscoring the continued relevance of traditional hardening against AI-driven threats.

Why it matters

AI-driven hacking can scale exploits instantly, putting thousands of institutions at risk.

In this story

AI agentsPaperCut vulnerabilitiesCVE-2026-81578CVE-2026-82078education sectorremote code executiondomain admincybercrimeIP 45.142.193.132security patches
Get the beta ↗