AI Agents Breached 395 Organizations via PaperCut Flaws

GreyNoise said in a report dated September 9, 2026 that a single threat actor used hundreds of autonomous AI agents to exploit two PaperCut NG/MF vulnerabilities, compromising at least 440 PaperCut instances belonging to 395 identified organizations across 48 countries. The campaign, which GreyNoise titled "Agents Gone Wild," began on August 31, 2026 and is the same wave of exploitation that security firms first flagged in late August.
The operators paired OpenAI's Codex harness with a DeepSeek model, and used them not only to write exploit code but to debug it, manage target lists and adapt the attack while it was running, GreyNoise said. Targets were sourced through the internet-scanning service Netlas, and the agents drove conventional offensive tooling once inside, including Mimikatz, BloodHound, Impacket, Certipy, Rubeus, NetExec and Ligolo-ng. The intrusion chain abused CVE-2026-81578, an authentication bypass, and CVE-2026-82078, a remote code execution flaw.
Why now: GreyNoise's report is the first detailed account of how far the campaign scaled and how fast it moved. The actor went from an empty workspace to remote code execution against a real victim in just under four hours, then reached domain administrator two hours after that. Once the operation hit full speed, GreyNoise recorded 11 organizations compromised in 26 seconds. At one US high school, BleepingComputer reported on September 10, the attacker went from initial access to full domain administrator in seven minutes.
Why it matters: the agents harvested credentials at 280 victim organizations, extracted operating system or domain secrets at 147, and obtained domain administrator rights at 12, according to Help Net Security and BleepingComputer. Education was the hardest-hit sector with 204 victims, and the United States the most affected country with 98, Help Net Security reported on September 11. For school and university IT teams, the practical change is the response window: an intrusion that compresses into minutes leaves no room for a next-morning patch cycle. PaperCut published fixes in its August 27 security bulletin, in versions 24.1.10, 25.0.13 and 26.0.5.
GreyNoise argues defenders are not powerless against agent-driven attacks. It documented at least one case in which a Cloudflare web application firewall defeated the adversary, and concluded that fundamental hardening still improves security posture against AI-enabled threats.
Significant unknowns remain. GreyNoise describes the operator only as "a likely Russian-speaking malicious cyber actor" and stops short of naming a group or a sponsor. None of the victim organizations have been identified publicly. And the automation was imperfect: the agents were configured to skip targets in an exclusion list of countries, but did not consistently follow those instructions.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.