GreyNoise has published an account of a campaign that began on 31 August. A threat actor pointed hundreds of agents, built on OpenAI's Codex and a DeepSeek model and wired to ordinary offensive tooling, at two vulnerabilities in PaperCut NG/MF — the print management software that sits on a great many school and university networks.
The agents built, tested and refined the exploits. From an empty workspace to remote code execution against a real victim took just under four hours. First domain admin came two hours after that. When the campaign proper ran, eleven organisations were compromised in twenty-six seconds.
The totals are 440 instances at 395 organisations in 48 countries, credentials taken from 280 victims, operating system or domain secrets from 147, and administrator privileges at 12. About half the victims were in education.
The exploit was not the achievement
It is worth being precise about what is new here, because "AI-powered attack" is a phrase that has been applied to a great deal that was not.
The vulnerabilities were real and were already flagged as actively exploited. The tooling was commodity. A competent human team could have written these exploits, and something like this campaign has been within reach of a well-resourced group for years.
What was not within reach was doing it in six hours with no team.
Why that particular constraint held everything else up
Nearly every assumption in defensive security is priced, implicitly, against attacker labour.
A patch window exists because after a vulnerability is disclosed there is a period during which exploitation is possible but not yet widespread — and it is not yet widespread because writing a reliable exploit, testing it against real configurations, and then finding and hitting targets at scale takes people and time. Defenders use that gap. It is the entire operating model of vulnerability management.
Prioritisation works the same way. Organisations trust that an attacker will go after the valuable targets first, because attention is finite. A school district's print server is not valuable, which is precisely why it has historically been safe.
Both of those depend on the attacker having to choose. An operator with hundreds of agents does not choose. It does all of them, and the marginal cost of the four-hundredth victim is close to the marginal cost of the first.
The victims tell you the same thing
Half of them in education is not a preference. It is what you get when selection stops being a cost.
PaperCut is widely deployed in schools and universities, frequently internet-facing, and maintained by IT teams who are chronically short-staffed. Under the old economics, that population was protected by being uninteresting. Under these, being numerous is the only selection criterion that matters, and being numerous is what they are.
This desk has written about the adjacent shape more than once — that installing a package runs its code, which is the design rather than the attack, and that everybody audits the package and nobody audits the shelf it sits on. In each case the system behaved exactly as specified and the specification was the problem. Here nothing was even subverted. Known flaws were exploited faster than anybody had planned for.
What defenders can actually change
Not patch speed, which is already the thing everyone is trying hardest at and which cannot go to zero.
The recoverable ground is exposure. A print server that is not reachable from the internet is not in this campaign regardless of how fast the agents work, and the number of organisations that have one exposed without needing to is large. Attack-surface reduction has always been the unglamorous half of this discipline, funded last because the risk it removes is invisible when nothing happens.
The second is credential blast radius. Credentials came out of 280 victims and domain secrets out of 147, which is the step that turns a compromised print server into a compromised network. That conversion is a configuration decision made long before any attack, and it is one an under-resourced team can get right once.
What to watch
Not the next campaign of this shape, which will come and will be reported as a first again.
Watch the interval between a CVE being published and mass exploitation being observed. That number has been shortening for a decade and everybody in the field knows it. If it collapses from days to hours as a matter of routine, then vulnerability management as currently practised — triage, schedule, test, deploy — stops being a defence and becomes a record of what happened, and the industry will need a different primary control.
The honest position today is that one campaign does not establish a trend. It does establish a capability, and capabilities of this kind do not get rarer.
The account of a campaign beginning 31 August 2026 using hundreds of agents built on OpenAI's Codex and a DeepSeek model together with commodity offensive tooling; the targeting of CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF; the compromise of at least 440 instances at 395 distinct organisations across 48 countries; the timings of just under four hours from an empty workspace to remote code execution, a further two hours to first domain admin, and eleven organisations compromised in twenty-six seconds; the harvesting of credentials from 280 victims, operating system or domain secrets from 147 and administrator privileges at 12; the concentration of roughly half the victims in education; and the attribution to a Russian-speaking threat actor are as published by GreyNoise in its report "Agents Gone Wild" and reported by BleepingComputer, Help Net Security, SC Media and Cybernews on 11 and 12 September 2026. PaperCut has issued patches replacing earlier emergency fixes. This publication has not independently verified the telemetry. The analysis is our own.
Topics aisecurityvulnerabilities





