Skip to content
Auto-CTI
Back to today
NEW Russian-speaking threat actor (unattributed; associated with GreyNoise intelligence) HIGH C3

PaperCut Flaws Exploited in AI-Powered Attacks

C SecurityWeek ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

A Russian threat actor group is using AI-generated exploits to automate and scale attacks against hundreds of PaperCut instances worldwide, combined with active post-exploitation for remote code execution and credential harvesting.

Description

Russian threat actors are exploiting two recent PaperCut NG/MF vulnerabilities through AI-orchestrated campaigns. Attackers used artificial intelligence to build, test, and deploy exploits against 440 PaperCut instances, targeting 395 organizations across 48 countries. The campaign aims at remote code execution (RCE) and harvesting of user credentials. Exploitation activity is intensifying with increased active intrusions on compromised systems. This demonstrates how threat actors leverage AI technology to accelerate and scale attack operations against critical infrastructure components.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
15.00
raw before weight
15.00
industry weight
1.10
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC