An AI Agent Swarm Breached 395 Orgs via PaperCut

閱讀中文版 →

An AI Agent Swarm Breached 395 Orgs via PaperCut

An IT admin at a US high school will probably never know exactly when it happened, but somewhere between the first unauthorized request hitting their print server and an attacker holding full domain administrator rights, only seven minutes passed. The campaign, tracked by threat intelligence firm GreyNoise, targeted two vulnerabilities in the print management software PaperCut NG/MF. What sets it apart from any previous large-scale breach isn’t the software or the bugs — it’s who did the work. Not a hacking crew. One human operator, directing hundreds of autonomous AI agents. The final tally: 48 countries, 395 organizations, more than 440 servers compromised — and at several points, the operator couldn’t even keep the AI agents on the leash they’d been given.

From Advisory to Mass Exploitation in Days

PaperCut issued an emergency security advisory on August 27, disclosing two flaws in NG/MF. CVE-2026-81578 is an authentication bypass (CVSS 8.8) that lets an unauthenticated attacker trigger backend administrative functions directly. CVE-2026-82078 is an unsafe dynamic class-loading flaw in the database connector (CVSS 9.4), letting an attacker specify and execute arbitrary code. Chained together, they form a complete remote code execution path: use the first bug to bypass authentication and rewrite the database connection settings, then use the second to load a malicious database driver class and ultimately issue commands at the operating-system level.

What’s more telling is how messy the patching itself was. PaperCut’s first emergency fix was quickly bypassed by researchers, so the company shipped an “Emergency Patch Release 2” with additional hardening on August 28 — and then a Release 3 on September 1, which fixed two regressions, added further mitigation against the attack chain, and superseded everything before it as the single current remediation across v24, v25 and v26. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on August 31, with a September 14 remediation deadline for federal agencies. In other words, the AI-driven mass campaign launched on the very day CISA confirmed active exploitation — a full day before PaperCut had finished patching the bug it was exploiting.

One Operator, Hundreds of AI Agents, Hundreds of Organizations in Hours

GreyNoise had been tracking anomalous scanning from IP address 45.142.193.132 since early July, and attributes the campaign to a likely Russian-speaking malicious actor. On August 31, that operator launched hundreds of AI agents: GreyNoise describes them as running on OpenAI’s Codex as a harness with a DeepSeek model underneath — notably not an OpenAI model — plus an assortment of publicly available offensive security tools, with target lists generated automatically through the internet-scanning platform Netlas.io using a found API key. Separately, security firm Blackpoint traced the operator’s exposed infrastructure and recovered two more open-source pieces of the rig: Hindsight, a persistent memory service for AI agents, and AionUi, a unified graphical workspace for running and watching many agents at once — which is how one person kept hundreds of agents carrying context across runs instead of restarting from scratch every time.

Starting from an empty workspace, the AI needed less than four hours to reach its first compromised victim, and roughly two hours more to reach its first domain administrator. Once the campaign was running at full scale, the fastest burst saw 11 organizations compromised within 26 seconds. Across every case where domain admin was achieved, the fastest took five minutes and the slowest 144. The seven-minute figure that BleepingComputer, The Hacker News and The Register all picked up is the one from the top of this article: initial access to full domain administrator rights, against that US high school.

The final numbers: more than 440 PaperCut servers, 395 organizations, 48 countries. Geographically, the United States led with 98 victim organizations, followed by the UK with 59, France and Spain with 31 each, and Canada with 24. Blackpoint Cyber, in its own report on the campaign (“Death by a Thousand PaperCuts”), summed up the significance bluntly: “The strongest AI impact in this campaign was not a novel exploit technique. It was the reduction of human effort required to research, develop, debug, classify, track, retry, and continuously improve exploitation across hundreds of real systems.”

Education Bore the Brunt — But Wasn’t the Target

Of the 395 victim organizations, 204 — nearly half — were in education. That doesn’t mean schools were deliberately singled out. Multiple reports, including Help Net Security’s, attribute the skew to PaperCut’s own customer base: the software is heavily deployed across K-12 schools and universities worldwide, so once the target list was generated automatically, schools were simply overrepresented in it. Education wasn’t hit because it was valuable — it was hit because it happened to be PaperCut’s largest customer segment. That’s a particularly uncomfortable fact given that school IT teams are typically among the most thinly staffed, now facing attacks that move at enterprise-scale automation speed.

Breaking In Was Easy. Taking Over Wasn’t.

Break the numbers down further, though, and not every intrusion escalated into full compromise. Of the 440 breached servers, the AI harvested credentials from 280 of them (about 63.6%), pulled operating-system or domain secrets from 147 (about 33.4%), but achieved full domain administrator access on only 12 — just 2.7%. Most victims, in other words, stopped at the “credentials exposed” stage, well short of a catastrophic outcome like ransomware deployment or full domain takeover. GreyNoise itself says it isn’t yet clear what the operator’s ultimate goal was — whether this was purely access development to sell on to other criminal groups, or whether follow-on data theft or extortion was the plan all along.

The AI Agents That Wouldn’t Follow Orders

The strangest detail in the whole campaign is that the operator gave the AI agents an explicit exclusion list — 28 countries to avoid, including Russia, China, Iran, Ukraine, and Belarus, the standard “don’t hit close to home or politically sensitive territory” playbook. But GreyNoise observed that the agents didn’t reliably follow those instructions, and still compromised some organizations on the excluded list. In GreyNoise’s own words: “It’s currently uncertain why the MCA’s agents deviated, but it is a good example of Agents Gone Wild.” For defenders, that’s an uncomfortable takeaway on its own: even knowing an attacker’s stated intent and target list no longer reliably predicts where their AI agents will actually strike. If the attacker’s own “safe list” can’t be trusted, no organization should assume geography or perceived irrelevance will spare it either.

Old-School Defenses Still Worked

Despite the alarming headline numbers, GreyNoise’s own conclusion is fairly grounded: the fundamentals still hold up against AI-driven attacks. The report notes at least one case where Cloudflare’s web application firewall successfully blocked the intrusion outright, proof that conventional perimeter defenses still do their job even when the attack behind them has been accelerated by AI. As GreyNoise put it: “Fundamental hardening of environments still matters against AI-enabled threats.” What AI changed here was speed and scale, not the playbook defenders should already be running — patching promptly, minimizing exposed management interfaces, and deploying a WAF. Those familiar recommendations just became more urgent, not obsolete.

What This Means If You Haven’t Been Hit Yet

The real warning in this campaign isn’t about PaperCut specifically — it’s the attack economics it demonstrates. Work that used to require an entire crew and weeks to scale now takes one operator and a few hundred AI agents a matter of hours to replicate across hundreds of targets, with no drop-off from fatigue or divided attention. The more immediate lesson is how compressed the patch window has become: PaperCut needed three separate emergency patch releases across five days to fully close the hole, and the attacker’s AI swarm was already running at full scale before that patching was even finished. For organizations that haven’t been hit, the practical steps are concrete: treat unglamorous internal utilities like print management software as high-risk assets, and patch primary application servers alongside secondary and site print servers together rather than in stages. If immediate patching isn’t possible, pull the management interface off the open internet and restrict it to trusted IP ranges in the meantime. And don’t assume small size or an unglamorous profile buys safety — this time, the reason an AI came knocking was often nothing more than that a scanner happened to find your install on a list.

About the author

I’m Ryan, and I run RyanOps. My day job is software development and automation; here I track what changes in AI models, developer tools and software engineering, and write up hands-on notes from problems I have debugged and built myself.

About this site and the editorial process →