Published: · Region: Global · Category: cyber

AI-Driven Campaign Exploits PaperCut Flaws to Breach 440 Servers in 48 Countries

Attackers used hundreds of AI agents to chain together authentication bypass and remote code execution flaws in PaperCut, compromising at least 440 installations across 48 countries and in some cases gaining domain administrator access.

A global hacking campaign built around automated AI agents has turned a niche product weakness into a broad security problem for networks on almost every continent.

On 10 September, The Hacker News reported that attackers deployed hundreds of AI agents to compromise at least 440 PaperCut instances in 48 countries. PaperCut is a widely used print management system for corporate, educational and public‑sector networks. In at least 12 organizations, the intruders leveraged their foothold to reach domain admin level, giving them sweeping control over Windows environments.

The attackers chained two known vulnerabilities in PaperCut deployments. An authentication bypass flaw let them access systems without valid credentials. A separate remote code execution bug then allowed them to run arbitrary commands on those servers.

AI agents handled much of the work at scale: scanning for exposed PaperCut systems, exploiting the chained flaws and probing for ways to move deeper into networks. Instead of a small team manually picking targets, automation allowed the campaign to spread across dozens of countries using the same basic playbook.

For affected organizations, a compromised PaperCut server is more than a printing issue. It can expose document metadata and, more seriously, provide a launchpad for ransomware, data theft or long‑term espionage once attackers escalate privileges to domain admin.

The timing highlights a wider pattern. The US Cybersecurity and Infrastructure Security Agency (CISA) has just added serious flaws in Cisco, Citrix and Fortinet products to its catalog of actively exploited vulnerabilities. One Fortinet issue is suspected in a PivotC2 campaign that infected 178 devices, while a Cisco Firepower Management Center (FMC) bug can give unauthenticated attackers root access. Federal agencies face a 12 September deadline to patch.

Taken together, the PaperCut breaches and the CISA alerts show how quickly attackers can combine automation with unpatched edge systems to gain deep access. Once AI agents can handle repetitive scanning and exploitation at global scale, every internet‑facing management console — from print servers to security appliances — becomes a tempting entry point.

Key signals now will be how fast organizations patch or isolate vulnerable PaperCut servers, whether law enforcement attributes the campaign to a specific group, and how regulators and insurers respond to the demonstrated use of AI in broad exploitation campaigns.

Sources