A suspected threat actor, described as likely Russian-speaking, uses AI to develop exploits and carry out a wide-ranging campaign against vulnerable PaperCut NG/MF servers. Multiple reports attribute the activity to infrastructure associated with the IP address 45.142.193[.]132 and describe attempts to compromise large numbers of exposed instances.

Independent researchers, including Blackpoint Cyber and GreyNoise, say the exploitation targets security flaws disclosed recently in PaperCut NG/MF. Bleeping Computer reports the campaign compromises “395 organizations,” while The Hacker News describes compromise of “440+ instances.” Both accounts connect the activity to the use of hundreds of AI agents to identify weaknesses and execute intrusion attempts at scale, though they do not provide further technical details in the excerpts.

While the core facts align—AI-assisted exploit development, targeting newly disclosed PaperCut NG/MF vulnerabilities, and compromise of hundreds of organizations or instances—outlets differ in reported impact counts and how they frame the attribution based on observed traffic and intelligence from security firms.