Hundreds of AI Agents Helped One Attacker Breach 395+ Organizations via PaperCut Flaws
GreyNoise researchers uncovered a campaign in which a likely Russian-speaking threat actor used hundreds of AI agents — built on OpenAI's Codex harness, a DeepSeek model, and public offensive-security tools — to develop and deploy exploits for two PaperCut NG/MF print-management vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078.
At least 440 instances belonging to 395 identified organizations across 48 countries were compromised. The attacker harvested credentials from 280 victims, obtained OS or domain secrets from 147, and reached administrator privileges at 12 organizations. Target lists were generated automatically through the Netlas internet-scanning platform.
The pace was the real story: the operation went from an empty workspace to remote code execution on a real victim in under four hours, domain admin two hours after that, and once fully launched, compromised at least 11 organizations in 26 seconds — a scale and speed of attack that would have been implausible without AI agents doing the orchestration.
Photo of a Canon office printer via Wikimedia Commons, © Baron Maddock, licensed under CC BY 4.0.
Comments
No comments yet. Be the first to share your thoughts.
Leave a comment