Attacker used hundreds of AI agents to breach 395+ organizations via PaperCut vulnerabilities in hours
According to GreyNoise threat intelligence, an attacker powered by OpenAI's Codex and DeepSeek models exploited two PaperCut MF/NG bugs (CVE-2026-81578 and CVE-2026-82078) to compromise at least 395 organizations, concentrated in US education. The campaign achieved remote code execution in under four hours, domain admin access in six hours, and compromised 11 organizations in 26 seconds once launched. GreyNoise attributes the campaign to a likely Russian-speaking actor who developed exploits within days of PaperCut's emergency patches on August 28.
Topics
Sources
- Press Read article
Go deeper
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.