{"id":1627,"date":"2026-09-14T15:10:44","date_gmt":"2026-09-14T09:40:44","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1627"},"modified":"2026-09-17T09:40:31","modified_gmt":"2026-09-17T04:10:31","slug":"papercut-ai-attack-395-organizations","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/","title":{"rendered":"AI-Powered PaperCut Exploitation Hits 395 Organizations"},"content":{"rendered":"<p>A PaperCut AI attack compromised at least 440 PaperCut NG\/MF instances across 395 identified organizations in 48 countries. GreyNoise linked the campaign to a likely Russian-speaking threat actor using hundreds of AI agents to accelerate exploit development and deployment.<\/p>\n<p>The campaign targeted CVE-2026-81578, an authentication bypass, and CVE-2026-82078, an unsafe dynamic class-loading vulnerability.<\/p>\n<p>Together, the flaws created a path from unauthorized configuration changes to unsafe dynamic class loading. That chain could lead to code execution on vulnerable PaperCut servers.<\/p>\n<p>PaperCut has confirmed active exploitation and released security maintenance versions 24.1.10, 25.0.13, and 26.0.5. Organizations should upgrade to an appropriate fixed release rather than relying on the earlier emergency patches.<\/p>\n<h2>PaperCut AI Attack at a Glance<\/h2>\n<table style=\"font-weight: 400; width: 98.9127%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"14\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Information<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Affected product<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">PaperCut NG\/MF<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVEs<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVE-2026-81578, CVE-2026-82078<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVE-2026-81578<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Authentication bypass<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVSS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">8.8, CVSS v4.0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVE-2026-82078<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Unsafe dynamic class loading<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVSS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">9.4, CVSS v4.0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Confirmed exploitation<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Yes<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Compromised instances<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">At least 440<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Identified\u00a0organizations<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">395 across 48 countries<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Credentials harvested<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\">280 victims, including credentials recovered through LSASS memory and registry-secret dumping<\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">OS\/domain secrets obtained<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\">147 victims, including secrets used to support Active Directory privilege escalation<\/td>\n<\/tr>\n<tr aria-rowindex=\"13\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Domain admin reached<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">12 organizations<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"14\">\n<td style=\"width: 43.361%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Fixed releases<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 148.548%;\" data-celllook=\"0\"><span data-contrast=\"auto\">24.1.10, 25.0.13, 26.0.5<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>How Two PaperCut Flaws Created a Path to Code Execution<\/h2>\n<p>The campaign depended on two vulnerabilities with different roles.<\/p>\n<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-81578?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=papercut_ai_attack\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2026-81578<\/a> affects the PaperCut NG\/MF web management interface. PaperCut describes it as an improper <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/access-control-explained\/\">access-control<\/a> vulnerability. Under specific conditions, unauthenticated requests targeting administrative functions can trigger backend actions before access validation completes.<\/p>\n<p>As a result, a remote unauthenticated attacker can modify certain system configurations. The vulnerability carries a CVSS v4.0 score of 8.8.<\/p>\n<p><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-82078?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=papercut_ai_attack\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">CVE-2026-82078<\/a> affects PaperCut&#8217;s database connection utilities. The application could instantiate database driver classes using configurable driver names without validating them against an approved allowlist.<\/p>\n<p>An attacker who could manipulate those configuration parameters could execute arbitrary Java bytecode already present on the application classpath. That code runs under the security context of the PaperCut server process. PaperCut rates this vulnerability 9.4 under CVSS v4.0.<\/p>\n<p>Chaining the two weaknesses therefore connected unauthorized administrative configuration changes with code execution in the PaperCut server process.<\/p>\n<h2>Hundreds of AI Agents Compressed the PaperCut Attack Timeline<\/h2>\n<p>The distinguishing feature of this campaign was not simply that AI helped write malicious code.<\/p>\n<p>GreyNoise found that the adversary built a lab containing vulnerable PaperCut software and an Active Directory server. The attacker used that environment to develop and test exploitation before targeting real systems.<\/p>\n<p>Hundreds of AI agents then supported the operation at scale. GreyNoise reported that the infrastructure combined OpenAI&#8217;s Codex harness with a DeepSeek model. The attacker also used Netlas to generate target lists.<\/p>\n<p>The resulting attack tempo was unusually compressed.<\/p>\n<p>GreyNoise observed the adversary move from an empty workspace to <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-remote-code-execution-rce\/\">remote code execution<\/a> against a real victim in under four hours. Domain administrator access followed roughly two hours later.<\/p>\n<p>Once the full campaign launched, at least 11 organizations were compromised within 26 seconds. In one U.S. high school environment, initial access progressed to domain administrator privileges in seven minutes.<\/p>\n<p>However, domain-level escalation occurred in only a subset of compromised environments.<\/p>\n<h2>How PaperCut Compromise Reached Active Directory<\/h2>\n<p>GreyNoise documented three main routes from compromised PaperCut infrastructure toward domain-level privileges.<\/p>\n<p>First, attackers dumped LSASS memory and registry secrets from domain-joined PaperCut servers. Recovered credential hashes could then support pass-the-hash activity against domain controllers.<\/p>\n<p>Second, the adversary exploited noPac in environments that remained vulnerable to CVE-2021-42278 and CVE-2021-42287. Those older Active Directory vulnerabilities created another privilege-escalation route.<\/p>\n<p>Third, some environments exposed an even shorter path. Where PaperCut ran on a domain controller or under a domain administrator service account, the attacker could add a newly created account to the Domain Admins group.<\/p>\n<p>GreyNoise reported that after successfully reaching domain administrator privileges, the attacker used DCSync to replicate Active Directory credential data from domain controllers.<\/p>\n<p>The findings demonstrate why PaperCut&#8217;s deployment context matters. Compromise of the application can become considerably more serious when its server holds privileged credentials or operates with excessive domain permissions.<\/p>\n<h2>How the PaperCut AI Attack Progressed Beyond Initial Access<\/h2>\n<p>The compromise extended well beyond initial server access. Credential harvesting occurred on 280 victims, while researchers observed operating system or domain secrets obtained from 147.<\/p>\n<p>However, organizations should distinguish those figures from full domain compromise. GreyNoise observed domain administrator access at 12 organizations.<\/p>\n<p>The campaign&#8217;s final objective also remains unclear. GreyNoise said it could not determine whether the actor planned to retain or transfer access, steal data, deploy ransomware, or pursue another objective.<\/p>\n<p>Therefore, the confirmed incident should not be described as a ransomware campaign or confirmed data-theft operation.<\/p>\n<h2>PaperCut Recommends Moving to Security Maintenance Releases<\/h2>\n<p>PaperCut initially issued emergency patches as it investigated active exploitation. The vendor has since released full security maintenance versions that replace those emergency fixes.<\/p>\n<p>Organizations should upgrade to:<\/p>\n<ul>\n<li>PaperCut NG\/MF 24.1.10<\/li>\n<li>PaperCut NG\/MF 25.0.13<\/li>\n<li>PaperCut NG\/MF 26.0.5<\/li>\n<\/ul>\n<p>Administrators should also investigate PaperCut systems that were exposed while vulnerable.<\/p>\n<p>Because attackers targeted credentials and Active Directory after initial compromise, incident response should extend beyond installing the update. Teams should review the affected server&#8217;s security context, investigate suspicious credential access, and assess whether privileged accounts were exposed.<\/p>\n<p>Organizations should also avoid running PaperCut with unnecessary domain privileges. A compromised application should not automatically inherit authority that creates a direct route to domain administration.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Endpoint-Patch-Management-Blog-Cover-Image-1024x535-1-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Endpoint Patch Management: Reducing Security Risk Across Devices<\/h4><p>Learn how endpoint patch management helps IT teams improve update visibility, and reduce exposure.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/endpoint-patch-management\/\" aria-label=\"Endpoint Patch Management: Reducing Security Risk Across Devices\"><\/a><\/div><\/div><\/div>\n<h2>Where Hexnode Fits into PaperCut Incident Response<\/h2>\n<p>PaperCut itself must be upgraded through PaperCut&#8217;s supported server-update process. Hexnode UEM and Hexnode XDR support the surrounding endpoint management and incident-response layers rather than replacing that remediation.<\/p>\n<h3>Use Hexnode UEM to Maintain Endpoint Patch Posture<\/h3>\n<p>The campaign showed how unpatched weaknesses elsewhere in an environment can extend an initial application compromise.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> provides patch-management workflows for supported Windows and macOS devices. Administrators can identify missing updates, manage patch deployment, automate supported patch workflows, and review patch compliance.<\/p>\n<p>Hexnode UEM also supports custom script execution on managed Windows, macOS, and Linux devices. On managed Windows systems, administrators can use custom scripts for version checks and other administrative tasks.<\/p>\n<p>Where the PaperCut installer and deployment requirements are compatible, admins can also configure unattended deployment of the applicable PaperCut maintenance release.<\/p>\n<p>PaperCut supports command-line options for automated Windows installation, while Hexnode UEM supports Windows EXE deployment and custom installation parameters.<\/p>\n<p>However, PaperCut&#8217;s security maintenance release remains a PaperCut-specific remediation task unless its update is explicitly supported through an organization&#8217;s applicable Hexnode patch workflow.<\/p>\n<h3>Investigate Suspicious Endpoint Activity with Hexnode XDR<\/h3>\n<p>GreyNoise observed the attacker move from an empty workspace to remote code execution against a real victim in under four hours. That compressed timeline makes historical endpoint context valuable during retrospective investigation.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a>&#8216;s Advanced Investigation Query provides access to seven days of detailed endpoint data. Analysts can query historical endpoint activity to investigate events surrounding suspected initial access and subsequent activity. MITRE ATT&amp;CK Insights also maps detected threats to ATT&amp;CK techniques, adding technique-level context during investigation.<\/p>\n<p>If malicious endpoint activity is identified, documented response actions include device isolation, process termination, and file quarantine.<\/p>\n<p>These controls can support investigation and containment after suspicious activity reaches supported endpoints. They do not replace upgrading PaperCut, investigating Active Directory, rotating compromised credentials, or performing domain-level incident response.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-XDR-IS-stronger-thumbnail-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Why-XDR-IS-stronger-thumbnail\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            See how combining UEM context with XDR investigation and response can help IT and security teams strengthen endpoint protection and accelerate incident containment.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>What Enterprises Should Do After the PaperCut AI Attack<\/h2>\n<p>Organizations running PaperCut NG\/MF should prioritize several actions:<\/p>\n<ol>\n<li><strong>Upgrade<\/strong> PaperCut immediately to the applicable security maintenance release or a later secure version.<\/li>\n<li><strong>Identify<\/strong> previously exposed systems. Use available inventory records and, where appropriate, Hexnode UEM custom scripts to collect relevant system or application information from managed endpoints.<\/li>\n<li><strong>Investigate<\/strong> credential access on affected PaperCut servers and assess whether privileged credentials or Active Directory secrets were exposed.<\/li>\n<li><strong>Review<\/strong> PaperCut service-account privileges and remove unnecessary domain-level permissions.<\/li>\n<li><strong>Check<\/strong> Active Directory patch posture, particularly where older vulnerabilities could create additional escalation routes.<\/li>\n<li><strong>Investigate<\/strong> suspicious endpoint activity. On supported endpoints monitored by Hexnode XDR, use query-based investigation to review relevant historical activity. If malicious activity is confirmed, use documented containment actions such as device isolation where appropriate.<\/li>\n<li><strong>Rotate<\/strong> credentials where investigation identifies exposure and follow established incident-response procedures.<\/li>\n<\/ol>\n<p>The central lesson from this campaign is its speed. AI agents allowed one operator to move from exploit development to widespread exploitation on a compressed timeline.<\/p>\n<p>Yet the post-exploitation routes remained recognizable: credential dumping, pass-the-hash, unpatched Active Directory vulnerabilities, excessive service-account privileges, and DCSync.<\/p>\n<p>That makes the defensive priorities equally familiar. Patch exposed software quickly, reduce privileged access, investigate credential exposure, and maintain endpoint visibility before a server foothold becomes a domain-wide incident.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Endpoint Security Beyond the Patch<\/h5><p>Manage endpoint patch posture and bring device management into a broader security workflow with Hexnode.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A PaperCut AI attack compromised at least 440 PaperCut NG\/MF instances across 395 identified organizations&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1628,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,13],"class_list":["post-1627","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-security","category-identity-abuse","product_category-unified-endpoint-management"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PaperCut AI Attack Hits 395 Organizations<\/title>\n<meta name=\"description\" content=\"PaperCut AI attack exploited two flaws across 395 organizations, accelerating credential theft and domain compromise.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PaperCut AI Attack Hits 395 Organizations\" \/>\n<meta property=\"og:description\" content=\"PaperCut AI attack exploited two flaws across 395 organizations, accelerating credential theft and domain compromise.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-14T09:40:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-17T04:10:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"AI-Powered PaperCut Exploitation Hits 395 Organizations\",\"datePublished\":\"2026-09-14T09:40:44+00:00\",\"dateModified\":\"2026-09-17T04:10:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/\"},\"wordCount\":1414,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp\",\"articleSection\":[\"AI Security\",\"Identity Abuse\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/\",\"name\":\"PaperCut AI Attack Hits 395 Organizations\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp\",\"datePublished\":\"2026-09-14T09:40:44+00:00\",\"dateModified\":\"2026-09-17T04:10:31+00:00\",\"description\":\"PaperCut AI attack exploited two flaws across 395 organizations, accelerating credential theft and domain compromise.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"AI-Powered PaperCut Exploitation Hits 395 Organizations\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/papercut-ai-attack-395-organizations\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AI-Powered PaperCut Exploitation Hits 395 Organizations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PaperCut AI Attack Hits 395 Organizations","description":"PaperCut AI attack exploited two flaws across 395 organizations, accelerating credential theft and domain compromise.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/","og_locale":"en_US","og_type":"article","og_title":"PaperCut AI Attack Hits 395 Organizations","og_description":"PaperCut AI attack exploited two flaws across 395 organizations, accelerating credential theft and domain compromise.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-14T09:40:44+00:00","article_modified_time":"2026-09-17T04:10:31+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"AI-Powered PaperCut Exploitation Hits 395 Organizations","datePublished":"2026-09-14T09:40:44+00:00","dateModified":"2026-09-17T04:10:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/"},"wordCount":1414,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp","articleSection":["AI Security","Identity Abuse"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/","url":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/","name":"PaperCut AI Attack Hits 395 Organizations","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp","datePublished":"2026-09-14T09:40:44+00:00","dateModified":"2026-09-17T04:10:31+00:00","description":"PaperCut AI attack exploited two flaws across 395 organizations, accelerating credential theft and domain compromise.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/AI-Powered-PaperCut-Exploitation-Hits-395-Organizations.jpeg?format=webp","width":1340,"height":754,"caption":"AI-Powered PaperCut Exploitation Hits 395 Organizations"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/papercut-ai-attack-395-organizations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"AI-Powered PaperCut Exploitation Hits 395 Organizations"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1627","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1627"}],"version-history":[{"count":4,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1627\/revisions"}],"predecessor-version":[{"id":1697,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1627\/revisions\/1697"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1628"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1627"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1627"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}