Security research firm GreyNoise reported that a Russian-speaking threat actor used hundreds of AI agents, built on an AI coding harness paired with a large language model, to weaponize CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF print-management software, BleepingComputer and SecurityWeek reported.
The AI-orchestrated campaign compromised at least 395 organizations across 48 countries since August 31, 2026, with roughly half of victims in the education sector, according to GreyNoise’s research.
Why it matters: The scale and speed of an AI-agent-orchestrated exploitation campaign against a known, patchable vulnerability illustrates how AI coding tools are lowering the operational cost of mass exploitation for attackers, independent of whether the underlying vulnerability itself is novel — a trend security teams increasingly need to plan around rather than treat as a future risk.
Source: GreyNoise research, corroborated by BleepingComputer and SecurityWeek, September 10, 2026.

Leave a Reply