ZeroHour

Search: “Large Language Models”

365 stories

Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF

AI-orchestrated campaign exploited PaperCut NG/MF RCE (CVE-2026-81578/82078), compromising 440+ instances at 395 organizations in 48 countries.

GreyNoise tracked a likely Russian-speaking actor using AI (OpenAI Codex harness plus a DeepSeek model) to develop, test, and deploy exploits for PaperCut NG/MF (CVE-2026-81578, CVE-2026-82078) starting 31 August 2026. The actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, achieving domain admin at 12 victims — fastest time to domain admin was five minutes and a US high school was fully compromised in seven minutes. Attack paths involved LSASS memory and registry secret harvesting, pass-the-hash to domain controllers, noPac attacks, account additions to Domain Admins, and DCSync to exfiltrate full NTDS.DIT credential dumps. Impact scope suggests access development potentially for handoff, with prior PaperCut intrusions historically leading to extortion.

GreyNoise · 7d agoThreat actor in the wildCVE-2026-81578CVE-2026-82078CVE-2021-42278+1 CVEs1

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft warns of a high-volume phishing campaign using invisible Unicode characters to split keywords like 'funding' and evade filters, peaking at 2.37 million daily messages.

Microsoft's Security Research team documented a high-volume phishing operation inserting deprecated Unicode Tags characters (U+E0000-U+E007F) inside financial keywords such as 'funding' so literal-string and regex email filters stop matching them. The campaign ran on a weekly cadence with 1-2.37 million weekday messages between February and May 15, 2026, peaking on February 26, 2026. It used hundreds of disposable finance-themed sender domains and relayed mail through ActiveCampaign's click-tracking infrastructure (acemlnd[.]com, activehosted[.]com), lending legitimate platform reputation. Microsoft ties the activity to an AI-assisted SBA loan phishing campaign that Fortra's FIRE team disclosed in September 2025.

The Hacker News · 12d agoPhishing & fraud in the wild