AI Agents Are Now Hacking Your Network: What UK Small Businesses Must Do This Week

Threats & Attacks

AI Agents Are Now Hacking Your Network: What UK Small Businesses Must Do This Week

Two items from this week’s threat intelligence feed cut through the noise. The rest can wait.

The first: a suspected Russian-speaking actor deployed hundreds of AI agents against PaperCut NG/MF print management servers. 440 instances compromised. 48 countries. The attack ran in roughly 48 hours. The second: CISA added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities catalogue yesterday, confirming active exploitation in the wild.

Both matter to UK small businesses. Neither is theoretical.

Story One: AI-Assisted Exploitation at Scale

PaperCut is print management software. It sits in offices, universities, legal practices, accountancy firms. Many small businesses run it without thinking much about it. It handles print queues. It is background infrastructure.

Researchers reported this week that a suspected Russian-speaking actor used AI-assisted workflows, essentially deploying hundreds of automated agents, to identify vulnerable PaperCut instances and exploit two flaws (CVE-2026-82078 and CVE-2026-81578) at a scale and speed that human-operated attack campaigns cannot match. The result: 440 compromised servers across 48 countries in under 48 hours.

Let that number settle. 440 organisations. Under 48 hours. One attacker, multiplied by AI.

The underlying vulnerabilities are patchable. That is both the reassuring part and the damning part. Many of those 440 organisations had patches available and had not applied them.

This is not a story about an unstoppable zero-day. This is a story about what happens when patching is treated as optional.

What PaperCut users need to do: Check your installed version. Apply the latest security updates immediately. If you use a managed service provider and they manage your PaperCut deployment, contact them today and ask for written confirmation that patches have been applied. Do not accept a verbal assurance.

Story Two: Your Router May Already Be Compromised

MikroTik produces networking hardware that is extremely common in small business environments, hospitality venues, hotels, and light industrial settings. Their RouterOS operating system powers routers, switches, and wireless access points that quietly run UK business networks without much attention.

CISA added two MikroTik RouterOS vulnerabilities to its Known Exploited Vulnerabilities catalogue on 10 September 2026. These are not theoretical risks. CISA’s KEV catalogue lists vulnerabilities with confirmed, active exploitation.

The first, CVE-2026-86060, allows an attacker to manipulate command argument delimiters to change trusted policy masks. The practical result: privilege escalation. An attacker who can reach your router management interface can elevate their access to administrative level.

The second, CVE-2026-67277, is arguably worse in the short term. It affects the btest service in RouterOS and allows kernel memory disclosure and denial of service with no authentication required. An attacker does not need credentials. They need network access.

For a device that is frequently internet-facing, frequently managed via default credentials, and frequently left unpatched, that combination is significant.

MikroTik devices are particularly common in hospitality networks: guest Wi-Fi in hotels, restaurants, pubs. If you run a business where customers connect to your network, you may be running MikroTik hardware without knowing the brand name.

What to do: Identify whether you have MikroTik hardware on your network. Check the management interface, check the physical hardware labels, or ask whoever manages your network. If you have MikroTik devices, apply RouterOS updates immediately. Restrict management interface access to internal networks only. Disable the btest service if you do not use it. Change default credentials if you have not done so.

The Pattern Behind Both Stories

These two incidents share an underlying logic that matters more than the specific CVE numbers.

The time between a vulnerability being disclosed and it being exploited at scale has collapsed. The PaperCut attack demonstrates what happens when exploitation is automated and scaled through AI agents: the window for patching shrinks from weeks to hours.

This is not vendor fear-mongering. The data shows it. 440 servers. 48 hours. AI-assisted exploitation is not a future threat; it is the operational reality of this week’s attacks.

For UK small businesses, the practical implication is this: monthly patching cycles are no longer adequate for critical infrastructure components. Routers and print management software both qualify. Neither is glamorous. Both are attack surfaces.

The secondary implication: you need to know what is on your network. Both of these attacks targeted software and hardware that organisations frequently do not think about. Print management software. Networking hardware. Background infrastructure. If you cannot name the software and hardware that connects your business to the internet, you cannot assess whether you are exposed.

How Knowing This Gives Your Business an Edge

The businesses that will be hurt by these attacks are the ones that respond after the fact. The businesses that will avoid damage are the ones that spend 30 minutes this week confirming their exposure and applying patches.

That gap, between the businesses that act on threat intelligence and the businesses that wait, is a competitive advantage. If you supply services to larger organisations, demonstrating that you monitor and respond to active threats is increasingly a procurement differentiator. Supply chain security is now a standard question in enterprise vendor assessments.

Patching MikroTik this week is not just risk reduction. It is evidence of operational maturity.

Making the Case Internally

If you need to justify the time and cost of addressing these vulnerabilities to a director or budget holder, here are three points that land:

CISA confirmed active exploitation. This is not a vendor advisory, not a theoretical risk assessment. The US government’s cyber security agency has confirmed these vulnerabilities are being exploited right now. That is the clearest possible signal.

The PaperCut attack shows the speed of modern exploitation. 440 organisations in 48 hours is a measurable failure rate. If your organisation is running unpatched software, the question is not whether you will be targeted, but when the automated scan finds you.

The cost of patching is hours. The cost of a breach is not. A ransomware incident triggered through an unpatched router costs, on average, far more than a morning of IT maintenance. The ICO does not treat “we hadn’t patched yet” as a mitigating factor in breach notifications.

What to Do Before the End of This Week

  1. Identify your networking hardware. Ask your IT provider or MSP for a network asset list. If they cannot provide one, that is a separate conversation you need to have. You need to know what is on your network.

  2. Check for MikroTik devices. If you find any, escalate immediately. Apply RouterOS patches, restrict management interface access, disable unused services including btest, and confirm default credentials have been changed.

  3. Check whether you run PaperCut. If you do, confirm the installed version and apply patches. Ask your IT provider for written confirmation. CVE-2026-82078 and CVE-2026-81578 are actively being exploited.

  4. Review your patching schedule. If your current process patches systems monthly or quarterly, that cadence is inadequate for network-facing infrastructure. Critical patches for routers, firewalls, and management software should be applied within 72 hours of release.

  5. Ask your MSP the right question. Not “are we secure?” That question produces a useless answer. Ask: “Are our MikroTik devices patched against CVE-2026-86060 and CVE-2026-67277?” A specific question produces a specific, accountable answer.

Before you go: follow the show wherever you listen, leave a rating or review, and drop a comment with your thoughts. If you know someone running a small business who should hear this, share it with them. This week’s intelligence is too important to sit unread in a feed.

SourceArticle
CISAKnown Exploited Vulnerabilities Catalogue: CVE-2026-86060 and CVE-2026-67277 (MikroTik RouterOS)
The Hacker NewsPaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
The Cyber ExpressAI Agents Compromised 440 PaperCut Servers, Researchers Say
NIST NVDCVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters
NIST NVDCVE-2026-67277: MikroTik RouterOS Missing Authentication in btest Service
The Cyber ExpressEU’s 24-Hour Vulnerability Reporting Rules Take Effect Friday
The Hacker NewsCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Filed under

  • smb-security
  • uk-business
  • nation-state-attacks
  • remote-access
  • business-risk
  • supply-chain-risk
  • incident-response