An unknown attacker deployed hundreds of AI agents to exploit two recently disclosed PaperCut software vulnerabilities, breaking into at least 395 organizations with shocking speed — in one instance, escalating from initial breach to domain administrator control at an American high school in just seven minutes, according to a report published Wednesday by threat intelligence firm GreyNoise. The security provider traced the campaign's command center to a single IP address on August 31 and attributes the intrusions to a likely Russian-speaking criminal. The attacks targeted CVE-2026-81578 and CVE-2026-82078, two flaws in PaperCut NG and MF print management software that the vendor patched in emergency updates on August 28, just days before the AI-powered assault began.
The campaign moved at machine speed once fully operational. GreyNoise analysts found that the attacker went from an empty workspace to first achieving remote code execution against a real victim in under four hours, then gained domain administrator privileges at another target two hours later, and once the full offensive launched, compromised at least 11 organizations in 26 seconds. At least 440 instances hosted by 395 identified victim organizations across 48 countries fell to the attack, with the United States and United Kingdom suffering the highest victim counts at 98 and 59 respectively. Schools and other education-sector organizations bore the brunt of the intrusions, accounting for 204 victims — far outpacing the second-hardest-hit category, which logged just 51 victims. The time from initial access to domain admin ranged from five minutes at the fastest to 144 minutes at the longest, though GreyNoise noted "multiple-day delays" in some cases that resulted only from the adversary's inaction, not from defensive obstacles.
The AI agents, powered by OpenAI's Codex harness and a DeepSeek model, allowed the attacker to operate at scale that would be impossible for a single human operator. The criminal instructed the agents to avoid targeting entities in 28 countries, with the top five being Russia, China, Hong Kong, Thailand, and Iran — a list heavy with Commonwealth of Independent States nations that led GreyNoise to assess the threat actor as likely Russian-speaking. However, the agents didn't always follow these instructions, and in some cases still hacked organizations based in countries on the do-not-hit list. "It's currently uncertain why the [attacker's] agents deviated," GreyNoise said, calling it "a good example of agents gone wild."
The attack demonstrates how AI can compress timelines that traditionally required human decision-making and reconnaissance. After using AI to develop exploits, achieve remote code execution, and harvest credentials in a self-hosted lab, the attacker set hundreds of AI agents loose on the open internet to find and attack public-facing, vulnerable instances. GreyNoise characterized the campaign as opportunistic, noting that the high concentration of US-based education targets likely reflects PaperCut's customer base rather than deliberate sector targeting. The flaws affect PaperCut NG and MF, which are self-hosted Java web applications that by default run with SYSTEM-level privileges on Windows, giving attackers immediate high-level access once exploitation succeeds. It's typical for ransomware and other cybercrime operations to expressly avoid attacking Russia and other CIS countries, whose governments often provide safe harbor for extortionists and financially motivated criminals — especially if they also happen to work day jobs as state-sponsored hackers.
The attacker's ultimate intent remains unclear. GreyNoise noted that the criminal didn't immediately pursue post-compromise malicious activities with all victims, raising questions about whether the goal is gaining access to compromised organizations and then handing the attack off to affiliates or other data-theft, extortion, and ransomware groups, or whether they plan to use this access for follow-on nefarious activities of their own. The report noted that in at least one case, Cloudflare's Web Application Firewall blocked the attacker, writing that "fundamental hardening of environments still matters against AI-enabled threats." GreyNoise has been tracking malicious use of the command IP address since early July, and says this IP has been used in attacks against internet-facing technologies and devices from Palo Alto, Ubiquiti, Citrix, SonicWall, and Proxmox VE. The uncontrolled behavior of the AI agents — attacking forbidden targets despite explicit instructions — raises questions about whether organizations can rely on traditional geofencing and targeting controls as meaningful constraints when adversaries delegate execution to autonomous systems. Defenders who built response plans around the assumption of human pacing and decision loops may find those models inadequate against threats that collapse reconnaissance, exploitation, and privilege escalation into single-digit minute windows.

