CuraSec

Act active

AI-Scaled Campaign Exploits PaperCut NG/MF, Hits 395 Organizations

2026-09-11 14:58 UTC · BleepingComputer · read the source ↗ #papercut#active-exploitation#ai-attacks
  • Engineer — Act: PaperCut NG/MF is being actively exploited at scale with hundreds of organizations confirmed compromised; patch PaperCut to the latest version immediately and audit server logs for exploitation indicators of compromise.
  • SOC/IR — Act: This is an active, wide campaign — hunt for post-exploitation behavior on PaperCut servers (unusual process spawns, outbound connections from the print server) and expand scope to look for lateral movement from any PaperCut host since the campaign’s start date.
  • Leader — Act: With 395 confirmed victims and a suspected nation-state-adjacent actor, confirm whether PaperCut NG/MF is in your environment, demand a patching and compromise-assessment status from engineering, and prepare a brief for leadership given the likelihood of press and customer questions.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.