On September 8, 2026, the DICT and the Cybercrime Investigation and Coordinating Center ordered national agencies, government corporations, local government units, and critical infrastructure operators to complete a cyber readiness assessment within 24 hours (Source: DICT and CICC, 2026). The trigger was concrete. A hacktivist group claimed it held access to the Department of Migrant Workers Active Directory environment for over a month before reaching a domain controller (Source: Newsbytes.PH, 2026).
The 26-Second Window
A single operator's fleet of AI agents compromised at least 11 organizations in 26 seconds once the campaign hit full scale (Source: GreyNoise, 2026). That operator went from an empty workspace to its first remote code execution against a real victim in under four hours, then reached first domain admin two hours later.
The campaign touched at least 440 PaperCut NG/MF instances across 395 victim organizations in 48 countries (Source: GreyNoise, 2026). The adversary also tried to skip 28 named countries. That restraint failed in several cases, because the agents did not reliably honor the exclusion list.
The Philippines appears once in the published victimology, at the credential harvesting stage. That is a snapshot taken while the campaign was still running, against a country that reported 19.2 million compromised credentials in the first half of 2026 (Source: Viettel Cyber Security, 2026).
What the Attackers Actually Chained
The intrusion relied on two flaws: CVE-2026-81578, an authentication bypass, and CVE-2026-82078, an unsafe reflection bug leading to remote code execution (Source: GreyNoise, 2026). Neither is exotic. The danger came from where they lived.
PaperCut NG and MF run as self-hosted Java web applications with SYSTEM-level privileges on Windows by default, normally joined to Active Directory. A print server in that position is not a peripheral. It is a credential store with a web front end.
Education absorbed the worst of it, at 204 of the 440 compromised instances, with 7 reaching domain administrator (Source: GreyNoise, 2026). From there the operator walked three paths: harvesting LSASS memory for pass-the-hash, abusing the noPac technique where two older domain flaws sat unpatched, or adding an account to Domain Admins where PaperCut ran on a domain controller. All three ended in a full extraction of the domain credential database.
Where the AI Actually Moved the Needle
Blackpoint Cyber recovered the operator's development workspace. It began on August 31, 2026 with research comparing patched and unpatched PaperCut builds, and within hours that research became a multi-threaded validation tool (Source: Blackpoint Cyber, 2026).
That tooling processed up to 200 targets concurrently and recycled incomplete systems through as many as 100 retry rounds. Failures were not discarded. Of 291 classified failures, 161 triggered the exploit but never returned the expected output, 60 broke during administrator creation, and 56 failed on configuration update.
Blackpoint's conclusion reframes the threat: "The strongest AI impact in this campaign was not a novel exploit technique. It was the reduction of human effort required to research, develop, debug, classify, track, retry, and continuously improve exploitation across hundreds of real systems" (Source: Blackpoint Cyber, 2026).
The Philippine Numbers Behind the Advisory
The advisory did not land in a quiet environment. Viettel Cyber Security recorded 16,619 phishing attacks, 255 data breach incidents, and 21 ransomware cases in the Philippines from January to June 2026 (Source: Viettel Cyber Security, 2026).
Those incidents exposed roughly 335 million records, including a coordinated run against financial institutions that compromised about 99 million records. The same report counted 34,650 newly disclosed software vulnerabilities in six months, 77 rated high-impact for products used in the country. Unpatched systems remained the entry point.
What the 24-Hour Order Requires
Covered organizations must hand their agency head a one-page assessment covering their most serious risks, actions already taken, and assistance needed (Source: DICT and CICC, 2026). Priority measures include fixing critical vulnerabilities, enforcing multi-factor authentication on privileged accounts, removing unnecessary internet exposure, and confirming backups can actually be restored.
Readiness is classified green, amber, or red, and suspected serious incidents must be reported immediately rather than waiting out the window. "This exercise must produce protective action, not merely another compliance report," the agencies said, adding that reminding staff to be careful does not discharge the government's obligation to protect the systems entrusted to it. Yano.AI's read is simple: the useful output of a readiness sprint is a ranked list of what gets fixed this week.
The DICT is also building a Centralized CPAL Portal listing accredited assessment laboratories and certified equipment, under a framework covering ICT, operational technology, industrial control systems, and IoT devices (Source: Newsbytes.PH, 2026).
Hardening Is Not Obsolete
One detail cuts against the fatalism that usually follows AI-agent attack reporting. In at least one attempt, a web application firewall defeated the adversary outright (Source: GreyNoise, 2026).
GreyNoise states that organizations are not helpless against agentic attacks, and that traditional hardening has a measurable positive effect. The campaign's own numbers agree: only 12 of 440 compromised instances reached domain administrator, meaning most intrusions stalled short of full control. The end goal remains unknown, whether access development for resale or direct data theft and ransomware.
FAQ
Q: Is PaperCut the only software exposed to this style of attack?
A: No. The same source address had been tracked since early July 2026 for probing internet-facing systems from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE before PaperCut became the focus (Source: GreyNoise, 2026).
Q: Does a single Philippine victim mean local organizations are safe?
A: No. GreyNoise noted other real victims could not be attributed to a named organization, and its victimology is a snapshot rather than a closed case.
Q: Are the DMW intrusion claims confirmed?
A: No. The DMW and DICT have not released a technical assessment confirming whether attackers reached the systems described or whether data was copied or extracted (Source: Newsbytes.PH, 2026). Treat the one-month access claim as an allegation until findings are published.
Key Takeaway
The PaperCut campaign is not remarkable because AI found a new class of bug. It is remarkable because AI collapsed the labor cost of running hundreds of exploitation attempts, classifying what failed, and retrying with better tooling (Source: Blackpoint Cyber, 2026). Defenders who measure their work in quarters now compete against an adversary whose iteration cycle is measured in hours.
The DICT and CICC gave agencies 24 hours to produce a ranked assessment of their riskiest exposed systems. Your organization may not have received that advisory. The question worth answering this week is the same one: which of your internet-facing systems runs with elevated privileges, and how fast could you prove it is patched?
Sources
- GreyNoise: AI-orchestrated PaperCut campaign
- The Hacker News: 440+ PaperCut instances compromised
- Blackpoint Cyber: AI-driven exploitation at scale
- Newsbytes.PH: PH phishing and breach surge, H1 2026
- Newsbytes.PH: DICT, CICC 24-hour cyber checks
- Newsbytes.PH: DMW network access claims
- Newsbytes.PH: DICT CPAL testing lab portal

Top comments (0)