A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.

According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to unauthorized port scanning and brute-force attack attempts in recent weeks. It's worth noting the same IP address was also flagged by Arctic Wolf in connection with the same activity last week.

At its core, the opportunistic attacks exploit CVE-2026-81578 and CVE-2026-82078, a combination of an authentication bypass and remote code execution chain, to mainly target the education sector in the U.S., the U.K., France, Spain, Canada, Belgium, Portugal, Australia, Germany, and Switzerland.

"Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data," Arctic Wolf noted.

GreyNoise said it has been tracking the malicious use of the IP address since early July 2026 for probing internet-facing systems from vendors, including Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE.