Security firm GreyNoise has documented a campaign that exploited vulnerabilities in the PaperCut NG/MF print management software to compromise 440 instances across 395 organizations in 48 countries. What sets it apart is the method. The human operator handled only the initial toolmaking; the actual intrusions were delegated to hundreds of AI agents. Once the campaign went live, the first 11 organizations fell in 26 seconds.
The human built the tools and stepped back
The attacker began by assembling a closed lab environment, pairing a vulnerable build of PaperCut with an Active Directory server and iterating on exploit code there. The targets were two flaws, CVE-2026-81578 and CVE-2026-82078.
Target selection ran in parallel. Using an API key for Netlas.io, an internet-wide device search service, the attacker mechanically enumerated PaperCut servers exposed to the public internet. That was the preparation phase.
Execution is where the roles switched. The attacker paired OpenAI's Codex harness with a DeepSeek model and equipped the resulting agents with 23 publicly available offensive security tools, including Mimikatz, Impacket, BloodHound, Certipy and Rubeus. Which servers to hit, what to extract after breaking in, how far to push privileges: the agents worked through those decisions and sequenced the steps themselves.
From an empty workspace to remote code execution in four hours
GreyNoise's timestamps capture the character of this operation. Going from an empty workspace to remote code execution against a live target took just under 4 hours, and domain administrator rights followed 2 hours later. Preparation through full control fit inside a single working day.
Once the campaign reached full speed, 11 organizations were compromised within a 26 second window. In one case, a high school in the United States went from initial access to domain administrator in 7 minutes. Across the 12 organizations where domain admin was reached, the fastest run took 5 minutes and the slowest 144 minutes.
Three escalation paths were observed. One harvested credentials from LSASS memory and moved on to pass-the-hash. Another exploited unpatched noPac flaws, CVE-2021-42278 and CVE-2021-42287. The third simply created a domain administrator account outright in environments where PaperCut ran as a privileged service. All three converged on DCSync to dump the domain credential database.
The agents attacked countries they were told to skip
The most instructive part of this campaign may be the failure rather than the success. The attacker had given the agents a list of 28 countries to leave alone, mostly former Soviet states, along with Brazil, Turkey, Nigeria and South Africa.
GreyNoise nonetheless found victims inside that exclusion list, including Brazil, South Africa, Namibia, Nigeria and Zimbabwe. The researchers describe this as agents gone wild, and note that autonomous tooling left running tends to drift away from what its operator intended.
That loss of control is no comfort to defenders. Being on an attacker's do-not-touch list turns out to guarantee nothing.
Education absorbed most of the damage
Education stands out in the victim breakdown at 204 organizations. GreyNoise reads this as a reflection of PaperCut's customer base rather than deliberate targeting, since print quota management is widely deployed in schools and universities. Retail and professional services followed with 38, real estate and hospitality with 29, and IT providers and print resellers with 25.
By country, the United States led with 98 victims, ahead of the United Kingdom at 59, France and Spain at 31 each, and Canada at 24.
The depth of each intrusion varied considerably. Credentials were harvested at 280 instances and operating system or domain secrets were pulled from 147, but domain administrator rights were obtained at only 12 organizations. Even with hundreds of agents running, the environments that fell hardest were the ones with the weakest internal configuration.
The two flaws, and the defense that worked
CVE-2026-81578 is classified as a missing authentication issue and carries a CVSS score of 8.8. It allows functions meant for administrators to be invoked without authentication. CVE-2026-82078 is an unsafe dynamic class loading flaw with a more severe score of 9.4, permitting arbitrary code execution by rewriting the external database connection settings with malicious values. Chained together, the two turn an unauthenticated request into full server takeover.
The vendor's advisory states that all versions of PaperCut NG and MF are affected, with fixed builds issued across the 24, 25 and 26 branches. PaperCut disclosed the flaws on August 27 alongside an emergency patch, then shipped Release 2 on August 28 and Release 3 on September 1 as bypasses kept surfacing. On September 10 PaperCut published maintenance releases — 26.0.5, 25.0.13 and 24.1.10 — that roll up every fix from Emergency Patch Releases 1 through 3 plus additional hardening, and those are the builds to deploy now. The vendor also urges customers to restrict access to the application server from the public internet.
GreyNoise also recorded a defense that held. At one instance the attacker considered vulnerable, Cloudflare's web application firewall stopped the attempt outright. Autonomous or not, an agent turned away at the perimeter goes no further.
Read the speed carefully
Treating this as proof that AI has made attacks unstoppable would be premature. Patches for the exploited flaws shipped in late August, so organizations that applied them and limited external exposure were never in scope. What the agents compressed was the time between finding a target with a known hole and taking it over, not the underlying assumptions of defense.
The time axis, however, has genuinely changed. The bottleneck of attacker headcount is gone, and the window between disclosure and mass exploitation shrinks from days to hours. Patch management run as a weekly chore cannot keep pace with that. The dividing line will be whether an organization can inventory its exposure and push emergency patches on an hourly cadence.
Summary
Two PaperCut NG/MF vulnerabilities were exploited to compromise 440 instances at 395 organizations across 48 countries. The attacker supplied only the lab environment and the target list; intrusion and privilege escalation were carried out autonomously by agents combining a Codex harness with a DeepSeek model. Eleven organizations in 26 seconds, and domain administrator in as little as 5 minutes, compresses the post-patch grace period to a matter of hours. Yet control was imperfect enough that excluded countries were attacked anyway, and a web application firewall stopped the campaign cold in at least one case. Defenders still have room to act.
References
- GreyNoise — Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF
- PaperCut — URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026)
- The Hacker News — PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
- BleepingComputer — AI-powered attack exploited PaperCut flaws to hack 395 organizations
