PaperCut campaign revision: AI-orchestrated exploitation expands compromise evidence
Published 11 Sep 2026 · Severity: critical
This draft revises the published PaperCut Pulse with new campaign evidence; it does not describe a new vulnerability or silently replace the earlier interpretation. GreyNoise reported on 9 September 2026 that a malicious actor used hundreds of AI agents and public offensive tools to exploit CVE-2026-81578 and CVE-2026-82078. GreyNoise observed at least 440 compromised PaperCut instances across 395 identified organisations, credential harvesting in 280 instances and domain-administrator access in 12. The findings reinforce immediate Release 3 deployment, exposure reduction and compromise investigation.