Claude Authentication Bypass
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to
What Happened
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to
Why This Matters
The evidence matters to defenders using Claude because it could allow access without the expected authentication controls.
Recommended Action
Confirm whether sep is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Sep 10, 2026 17:11
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.
Timeline
-
Incident first seen
Sep 10, 2026 17:11BugSkan first recorded this incident.
-
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Sep 10, 2026 17:11thehackernews.com · Vulnerability
Sources
thehackernews.com · Sep 10, 2026 17:11
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.