Last seen September 10, 2026

Claude Authentication Bypass

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

Technical Severity
Low severity
Lifecycle Status

NEW

What Happened

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

Why This Matters

The evidence matters to defenders using Claude because it could allow access without the expected authentication controls.

Recommended Action

Confirm whether sep is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Sep 10, 2026 17:11

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

Amazon AWSAnthropicGoogleMetaMicrosoftOpenAI

Authoritative Intelligence

CVE CVE-2026-81578, CVE-2026-82078 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.

GitHub API error: API rate limit exceeded for 68.178.145.130. (But here's the good news: Authenticated requests get a higher rate limit. Check out the documentation for more details.)

Timeline

  • Incident first seen
    Sep 10, 2026 17:11

    BugSkan first recorded this incident.

  • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
    Sep 10, 2026 17:11

    thehackernews.com · Vulnerability

Sources

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

thehackernews.com · Sep 10, 2026 17:11

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence