INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
PaperCut Fixes Two Actively Exploited Flaws
| 2026-09-11 07:56 CRITICAL MEDIUM EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On September 11, 2026, a suspected Russian-speaking threat actor was found to be weaponizing two actively exploited flaws in PaperCut's software, CVE-2026-81578 and CVE-2026-82078, to break into at least 395 organizations across 48 countries, with the majority concentrated in the U.S. education sector. The attacks utilized hundreds of AI agents powered by OpenAI’s Codex harness and a DeepSeek model to target organizations at scale while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. This ransomware attack is believed to have originated from an IP address "45.142.193[.]132."
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-81578, CVE-2026-82078 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
45.142.•••.•••
pa•••••.html
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-81578CVE-2026-81578
CVE-2026-82078CVE-2026-82078
Target & Sectors
TH
HK
RU
CN
IR
educationeducation
Incident Timeline
Sep 11, 2026
Threat actors exploited two actively known vulnerabilities in PaperCut, prompting the vendor to replace emergency patches with fixes for these flaws.
2026/09/11
Threat actors used hundreds of AI agents powered by OpenAI's Codex harness and a DeepSeek model to target organizations at scale, bypassing authentication and executing arbitrary code on susceptible instances.
Click on any entity below to view its context and source!
organisation
GreyNoise
"
"It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment," GreyNoise said.
organisation
PaperCut Replaces Emergency Patches With Fixes
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws.
organisation
Actively Exploited Flaws
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws.
victims
395 organizations
In one case highlighted by
GreyNoise and Blackpoint Cyber
, a suspected Russian-speaking threat actor has been found weaponizing the two flaws to break into at least 395 organizations in 48 countries, most of them concentrated in the
U.S. education sector
.
organisation
OpenAI’s
The attacks used hundreds of AI agents, powered by OpenAI’s Codex harness and a DeepSeek model, to target organizations at scale, while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries.
infrastructure
26.0.5
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
infrastructure
25.0.13
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
infrastructure
24.1.10
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
organisation
PaperCut NG/MF
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
organisation
CVE-2026
The vulnerabilities,
CVE-2026-81578 and CVE-2026-82078
, have come under active exploitation in the wild to bypass authentication and execute arbitrary code on susceptible instances.
organisation
Vulnerability / Cyber Attack
Ravie Lakshmanan
Sep 11, 2026
Vulnerability / Cyber Attack
PaperCut on Thursday
released
a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.
organisation
PaperCut
Ravie Lakshmanan
Sep 11, 2026
Vulnerability / Cyber Attack
PaperCut on Thursday
released
a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.
organisation
QA
"These are Regular Maintenance Releases (MR) that have gone through complete QA testing," it said.
organisation
IP
The activity originates from the IP address "45.142.193[.]132.
Tactical Metrics
Metrics
victims
395
Organizations
Click for context!
In one case highlighted by
GreyNoise and Blackpoint Cyber
, a suspected Russian-speaking threat actor has been found weaponizing the two flaws to break into at least 395 organizations in 48 countries, most of them concentrated in the
U.S. education sector
.
Metrics
infrastructure
26.0.5
Software Version
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
Metrics
infrastructure
25.0.13
Software Version
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
Metrics
infrastructure
24.1.10
Software Version
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
Intelligence Sources
The Hacker News
2026-09-11
AlienVault OTX
2026-09-11
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-11T10:47
Comprehensive Tactical Telemetry
Highly Correlated Entities
10x
organisation
Identified Entity
PaperCut Replaces Emergency Patches With Fixes
entity
5x
target region
Target Country
Russian Federation
country
3x
infrastructure
Software Version
26.0.5
version
2x
timeline
Temporal Reference
Sep 11, 2026
date
2x
vulnerability
Exploited CVE
CVE-2026-81578
cve
2x
general metric
Emergency Patch Releases
1
emergency patch releases
Contextual Telemetry
Context Block
7 METRICS
tactic
Cyber Operation Type
Ransomware
tactic
source region
Origin Country
Russian Federation
country
industry
Targeted Sector
Education
sector
victims
Organizations
395
organizations
general metric
Countries
48
countries
general metric
Other Countries
23
other countries
general metric
Sep
11
sep
Click on any entity below to view its context in the main text!
Selective Unpublish
Select the networks you want to remove this post from. The system will try to delete the real post through the API and clean the database so you can publish it again.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.