cyberivy
PaperCutAI SecurityAI AgentsGreyNoiseActive DirectoryVulnerability ExploitationCodexDeepSeek

Hundreds of AI agents accelerate attack on 395 organizations

September 11, 2026

Dunkle Illustration eines geöffneten PaperCut-Servers, umgeben von vernetzten roten Angriffsknoten und digitalen Verbindungslinien.

An attacker used Codex, DeepSeek and commodity offensive tools against unpatched PaperCut servers. GreyNoise says at least 395 organizations across 48 countries were hit.

What this is about

A suspected Russian-speaking attacker used hundreds of AI agents to exploit two vulnerabilities in PaperCut NG/MF. GreyNoise documented at least 440 compromised instances belonging to 395 organizations in 48 countries on September 10, 2026. Roughly half of the victims were in education.

The case matters because AI did more than suggest code. Agents assisted research, exploit development, testing, target selection, failure analysis and repeated attack waves, turning separate tools into a persistent exploitation pipeline.

What the attack actually does

The campaign chained CVE-2026-81578 and CVE-2026-82078 into authentication bypass and remote code execution. According to GreyNoise and Blackpoint Cyber, observed work began on August 31. The attacker first built a lab with PaperCut and Active Directory, developed tools there and generated target lists through Netlas.

Hundreds of agents then ran with OpenAI Codex, a DeepSeek model and established tools including Mimikatz, BloodHound, Certipy and Impacket. GreyNoise reports stolen credentials at 280 victims, operating-system or domain secrets at 147, and domain-administrator access at twelve organizations. It took just under four hours to move from an empty workspace to code execution against a real victim. Once the campaign launched, at least eleven organizations were compromised in 26 seconds.

Why it matters

The basic exploitation techniques were not new. The change was lower human effort: agents could classify failures, preserve context, adapt tools and retry targets. Small teams can therefore run campaigns that previously demanded more people and time.

For operators of internet-facing administrative software, the window between disclosure and mass exploitation is shrinking. PaperCut issued emergency updates. Operators of unpatched NG or MF systems must not only update but investigate whether credentials or Active Directory secrets have already been exposed.

In plain language

The attack resembles a burglary crew where hundreds of helpers test locks at the same time, share notes and improve their tools after each failure. No helper needs to understand the whole plan. Their shared notebook lets the next attempt start where the previous one stopped.

A practical example

A school runs a PaperCut server connected to Active Directory. After initial code execution, one agent collects configuration data, another tests credentials and a third records failed steps. In one real school case, GreyNoise says the attacker reached domain-administrator access in seven minutes. A patch is no longer enough: the IT team must isolate the server, preserve logs, reset accounts and investigate movement through the network.

Scope and limits

  • GreyNoise could not determine the campaign's final objective. Access resale, data theft or ransomware are possible, but none is yet established.
  • The suspected Russian-speaking attribution rests on indicators and is not a conclusive identity.
  • AI accelerated the operation but was not its only cause. Unpatched public systems and privileged service accounts enabled the impact.

SEO & GEO keywords

PaperCut NG/MF, CVE-2026-81578, CVE-2026-82078, GreyNoise, AI agents, Codex, DeepSeek, Active Directory, cyberattack, patch management

💡 In plain English

An attacker used hundreds of AI agents together against unpatched PaperCut servers. Operators need to update immediately and also look for credentials that may already have been stolen.

Key Takeaways

  • At least 395 organizations across 48 countries were affected.
  • Hundreds of agents connected research, development, targeting and retries.
  • Twelve organizations lost domain-administrator control, according to GreyNoise.
  • Installing a patch does not undo an existing compromise.
  • The attacker's objective and identity remain unresolved.

FAQ

Which PaperCut flaws were exploited?

The campaign chained CVE-2026-81578 and CVE-2026-82078 for authentication bypass and code execution.

Is installing the update enough?

No. Operators should also inspect logs and accounts because credentials may already have been stolen.

What role did AI play?

Agents supported nearly the entire workflow from research to retries, although the underlying attack techniques were established.

Sources & Context