Hundreds of AI agents exploited PaperCut flaws to breach 395 organizations in 48 countries
GreyNoise says a likely Russian-speaking operator used OpenAI Codex and DeepSeek models to build exploits, pick targets, and reach domain admin at one US high school in seven minutes.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
A threat actor used hundreds of AI agents to develop and run a global exploitation campaign against PaperCut NG and MF print management servers, according to threat intelligence firm GreyNoise. The agents built, tested, and refined exploits for CVE-2026-81578 and CVE-2026-82078, two flaws flagged as actively exploited earlier this month, and generated target lists through the Netlas scanning platform. GreyNoise traced the campaign's orchestration to a single IP address on August 31 and says the operator combined OpenAI's Codex harness and a DeepSeek model with commodity offensive tools. The adversary went from an empty workspace to remote code execution on a real victim in under four hours and to domain admin two hours later. GreyNoise data shows at least 440 compromised PaperCut instances tied to 395 organizations across 48 countries. Credentials were harvested from 280 victims, operating system or domain secrets from 147, and administrator privileges obtained at 12. Roughly half the victims were in education, and the United States was the most targeted country, followed by the United Kingdom, France, Spain, and Canada. In one case an American high school was taken from initial access to domain admin in seven minutes. The operator instructed the agents to avoid countries including Russia, China, Iran, and Ukraine, but the agents did not consistently follow those rules. The Hacker News reports PaperCut has replaced its emergency patches with full fixes for both flaws.
Sources
- BleepingComputerAI-powered attack exploited PaperCut flaws to hack 395 organizations
- theregisterHundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
- The Hacker NewsPaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
- The Hacker NewsPaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances