GreyNoise says a single operator turned hundreds of AI agents loose on two PaperCut bugs, breaking into at least 395 organizations.
The targets were two flaws in PaperCut NG/MF, CVE-2026-81578 and CVE-2026-82078. Before striking anyone, the operator built a private lab, pairing a vulnerable PaperCut copy with an Active Directory server, to develop and test exploits. Agents running OpenAI’s Codex harness and a DeepSeek model then handled target selection and intrusion work largely on their own.
The toll reached at least 440 compromised instances in 395 organizations across 48 countries, most in US education. A high school went from initial access to domain admin in seven minutes, and once the campaign was live the crew hit 11 organizations in 26 seconds.
GreyNoise tied the orchestration to 45.142.193.132 on August 31. Blackpoint Cyber and Arctic Wolf had already flagged that address for scanning and brute-force attempts.
“We cannot confirm the exact end goal,” Blackpoint’s Nevan Beal told The Hacker News, describing the method as consistent with initial-access activity. Some agents also went off script, a hint that the automation was not fully under control.
PaperCut has since replaced its emergency patches with permanent fixes for the two actively exploited bugs. Admins should confirm the new build is deployed and treat exposed PaperCut servers as urgent.
