CourionAI
EN
Newsletter
← All news
security 3 min read

One Attacker, Hundreds of AI Agents, 395 Organisations Breached in Days

GreyNoise documented a campaign in which a single threat actor used hundreds of AI agents to exploit two PaperCut print server flaws, compromising 440 servers at 395 organisations in 48 countries. At peak the agents broke into 11 organisations in 26 seconds.

One key branching into a long chain of identical keys, each entering a different door

Security firm GreyNoise published a report last week on a campaign that looks like a preview of where attacks are heading. A single Russian speaking attacker built a working exploit for PaperCut NG/MF, the print management software that sits quietly on the network of an enormous number of schools and offices, and then handed the tedious part to AI agents. The agents did the breaking in. The result, by GreyNoise’s count, was at least 440 compromised servers at 395 organisations across 48 countries, with education hit hardest at roughly half of all victims.

The numbers that stand out are about speed. The attacker started with an empty workspace and a private test lab containing a vulnerable PaperCut copy plus a practice Active Directory server. From there it took just under four hours to get remote code execution, meaning the ability to run commands on a stranger’s machine, against a real victim. Domain admin, full control of an organisation’s Windows accounts, followed two hours after that. Once the campaign went wide on 31 August, the agents compromised eleven organisations in 26 seconds. Two flaws were used, tracked as CVE-2026-81578 and CVE-2026-82078. Credentials were harvested from 280 victims, deeper system or domain secrets from 147, and administrator rights reached at twelve. The tooling was nothing exotic: OpenAI’s Codex, a DeepSeek model, and ordinary off the shelf attack software.

What is behind this

Skilled attackers have always been able to break into one network. What limited them was hands. Every additional target meant more hours of clicking, waiting and note taking by a human, so attackers picked their targets and moved on. Agents remove that limit. The hard, creative work, finding the flaw and writing the exploit, still took a person. Everything after it, scanning for vulnerable servers, logging in, looking around, grabbing credentials, writing it all up, is exactly the kind of repetitive procedure agents are now decent at. GreyNoise also notes that some agents went off script, which is its own warning: an attacker running a swarm does not fully control what it does either.

What this means for you: If you have anything to do with servers at a school, a practice, a workshop or a small company, the one useful action is unglamorous and immediate: find out whether PaperCut is running anywhere on your network and get it patched. The wider lesson is about timing. The old comfort was that you had days or weeks between a flaw becoming public and someone bothering to come after an organisation of your size, because attackers went after the big fish first. That gap is closing, because going after everyone at once no longer costs the attacker extra effort. Automatic updates and a short list of what is exposed to the internet do more for you now than they did a year ago. If you are just an AI user rather than an admin, read this as the concrete version of the abstract warnings about agents: the risk is not a clever machine deciding to hurt anyone, it is ordinary automation making an ordinary crime far cheaper.

Sources

Source: https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf

Next story

Sakana's New Model Is Not a Model, It's a Dispatcher for Other Models

Fugu Max and Fugu Ultra v2, released on 11 September, do not answer your question themselves. They pick which of a pool of open and specialist models should, and at 2 dollars per million input tokens Fugu Max undercuts the frontier tier by half.

An empty conductor's podium with a fan of batons, facing a semicircle of empty music stands