← Back to Daily Briefing

A sophisticated cyberattack campaign is utilizing autonomous and semi-autonomous AI-orchestrated multi-agent systems to exploit vulnerabilities in PaperCut NG and MF print management software. The campaign employs specialized AI agents to automate reconnaissance, execute complex exploits, and manage lateral movement within targeted networks. This orchestration has allowed attackers to bypass initial emergency security patches, resulting in the compromise of 440 servers across 395 organizations in 48 countries. The threat represents a high risk of sensitive data exfiltration through print spoolers and subsequent network penetration. To mitigate this, PaperCut has issued comprehensive Regular Maintenance Releases (MR) to address the sophisticated exploitation techniques used by these agents.

  • Incident/Breach Overview

    • Scale: 395 organizations across 48 countries have been confirmed breached.
    • Infrastructure: At least 440 individual servers have been compromised globally.
    • Target: Critical PaperCut NG and MF print management software environments.
  • Attack Vector & Campaign Mechanics

    • AI Orchestration: Use of multi-agent systems to conduct autonomous reconnaissance and lateral movement.
    • Agent Architecture: Sophisticated communication protocols and orchestration logic used for seamless task handoffs between agents.
    • Evasion Tactics: Deployment of specialized payloads designed specifically to bypass initial emergency vendor patches.
    • MITRE ATT&CK Mapping: Behavior aligns with T1588.005 (Autonomous Agents) for automated operational execution.
  • Risk Profile & Technical Impact

    • Data Exfiltration: High risk of sensitive document interception via manipulation of print spoolers.
    • Network Penetration: Exploitation of print management infrastructure to serve as a pivot point for deep lateral movement into corporate networks.
    • Attack Velocity: AI-driven automation significantly increases the speed and scale of exploitation compared to traditional automated kits.
  • Detection & Remediation

    • Mandatory Patching: Organizations must pivot from superseded emergency patches to comprehensive Regular Maintenance Releases (MR).
    • Critical Versions: Required updates include MR versions 26.0.5, 25.0.13, and 24.1.10.
    • Defensive Monitoring: Focus on identifying AI-agent-specific log signatures, malicious domains, and unique file hashes associated with the orchestration layer.

Related posts

  1. techjacksolutions.com — AI-Orchestrated Multi-Agent Campaign Exploits PaperCut NG/MF Flaws, Breaches 395 Organizations Globally
  2. techjacksolutions.com — PaperCut Vulnerability Rollup (2026-09-11)
  3. gbhackers.com — Hackers Deploy Hundreds of AI Agents to Compromise 440 PaperCut Servers
  4. bleepingcomputer.com — AI-powered attack exploited PaperCut flaws to hack 395 organizations
  5. Blog
  6. Hackread
  7. thehackernews.com — PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
  8. Reddit
  9. Securityweek
  10. Helpnetsecurity

LINK COPIED TO CLIPBOARD