<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[AI-powered attack exploited PaperCut flaws to hack 395 organizations]]></title><description><![CDATA[<p dir="auto">A threat actor, described as likely <strong>Russian-speaking</strong>, leveraged hundreds of <strong>AI agents</strong> to build and run a global exploitation campaign against vulnerable <strong>PaperCut NG/MF</strong> servers, ultimately compromising <strong>395 organizations</strong>.</p>
<p dir="auto">The operation stands out less for any single novel flaw and more for how automation was used to scale reconnaissance, vulnerability discovery, and exploitation across a large number of targets. Rather than manually probing each victim, the actor reportedly relied on fleets of AI agents to handle repetitive tasks and accelerate the attack lifecycle.</p>
<p dir="auto">Key points from the reporting:</p>
<ul>
<li>Target: internet-exposed <strong>PaperCut NG/MF</strong> print management servers</li>
<li>Method: exploitation of known PaperCut vulnerabilities at scale</li>
<li>Scale: <strong>395 organizations</strong> impacted worldwide</li>
<li>Attribution: likely <strong>Russian-speaking</strong> threat actor</li>
<li>Notable element: use of hundreds of <strong>AI agents</strong> to develop and conduct the campaign</li>
</ul>
<p dir="auto">For defenders, the familiar fundamentals still apply: inventory any <strong>PaperCut NG/MF</strong> instances reachable from the internet, confirm they are patched against known vulnerabilities, and restrict exposure where printing infrastructure does not need to be publicly accessible. Given the automated nature of this campaign, delays in patching and asset tracking are exactly the gaps such tooling is designed to find.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Does your organization run PaperCut NG/MF, and if so, is it exposed to the internet or kept internal-only?</p>
]]></description><link>https://xploitlk.com/topic/287/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:34:36 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/287.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 10 Sep 2026 16:30:30 GMT</pubDate><ttl>60</ttl></channel></rss>