// threat intel

Hundreds of AI agents breached 440 PaperCut servers: the patch window just collapsed to minutes

On 31 August the thing researchers had been warning about finally happened at scale: an attack where hundreds of AI agents did the grunt work a human crew used to do. According to GreyNoise, a single operator wired together OpenAI’s Codex and DeepSeek models, the Netlas internet-scanning platform and an ordinary kit of offensive tools, and in a matter of hours compromised at least 440 PaperCut print-management servers across 395 organisations in 48 countries. The scary part is not the breach itself. It is the speed: six hours from launch to the first domain takeover, and once the pipeline was running, 11 organisations fell in a 26-second burst.

What happened: PaperCut, two CVEs and an army of agents

PaperCut is a widely deployed print-management system that sits in schools, universities and companies, and all too often faces the open internet. The attacker went after two fresh flaws: the critical CVE-2026-82078 (CVSS 9.4) and an authentication bypass, CVE-2026-81578 (CVSS 8.8). Chained together they yield remote code execution on the server, and from there it is network recon, credential theft and domain compromise.

The novelty is how the operation was assembled. The AI agents were not there to chat. They were given concrete engineering work: write exploits for both CVEs, test and refine them, and use Netlas to build target lists across the whole internet. Work that takes one human days was run in parallel, around the clock, by a fleet of agents. The human set the objective and collected the results; everything in between ran itself.

Campaign metric Value
Launch to first remote code execution < 4 hours
To first domain-admin takeover 6 hours
11 organisations compromised in one burst 26 seconds
Full domain takeover at a US high school 7 minutes
PaperCut servers compromised 440
Organisations affected across 48 countries 395
Credentials harvested from 280 victims
OS or domain secrets obtained from 147 victims
Administrator privileges obtained at 12 organisations
Share in the education sector ≈ 50% (204 systems)
Speed and scale of the PaperCut campaign, per GreyNoise

Why this is a turning point

Individual PaperCut bugs get fixed with a patch. What should worry you is something else: automation erased the defender’s last advantage — time. There used to be a gap between disclosure and mass exploitation. You had to understand the bug, write a working exploit, find targets, all by hand. Patch management lived inside that gap. Here the gap is almost gone: the AI writes and debugs the exploit, the AI finds the targets, and the campaign unfolds faster than most teams finish reading the vendor advisory.

This is not “AI invented new magic.” The vulnerabilities are ordinary, so are the tools. What is new is throughput. One operator got the firepower that used to take a whole crew, and they did not hit hand-picked targets — they sprayed. Whoever had not patched fell into that 26-second window.

Why schools took the hit

Roughly half the victims were educational organisations — 204 compromised systems. The reason is mundane: in schools and universities PaperCut is often exposed to the internet, rarely updated, and there is no dedicated security team. For a spray-and-pray campaign that is the ideal target: many identical, poorly defended, externally reachable installs. That is also where the most telling episode happened — a US high school, seven minutes from initial access to full domain-admin rights.

What this means for defense

The good news is that the defense is not exotic — only the speed requirement changed. The basics still hold:

  • Apply PaperCut’s emergency updates for CVE-2026-82078 and CVE-2026-81578 now. If the server faced the internet, assume it was already touched and check your logs for signs of compromise.
  • Take off the internet what has no business being there. A print system should almost never be reachable by the whole world — put it behind a VPN or at least an allow-list.
  • Shrink your own response window. If exploitation is now measured in minutes, a once-a-year assessment does not save you — continuous exposure monitoring does. The patch window is no longer yours to schedule.
  • Keep an incident-response plan ready: who to call, where the logs are, how to isolate the domain. In a campaign where domain admin takes seven minutes, your clock runs in minutes too.

AI is now on both sides

This story is one more data point in a long argument. The same models that help a developer will, in other hands, write exploits and hunt for targets — a shift we broke down in the state of AI cyber models. PaperCut is that capability in real-world attacks, for profit. The logic is simple: if offense is accelerating with AI, defense cannot stay manual.

And there is a second lesson that hits closer to home for anyone running agents of their own. The autonomy that made this campaign fast is the same autonomy you hand your coding agents every day. We have written about what an AI coding agent can actually do on your machine and how autonomous agents get turned into credential thieves. The answer is not to ban agents, it is to govern them: a runtime firewall that gates every dangerous action, asks before it runs, and writes a tamper-evident log. That is the core of the three lines of defense for AI agents, and the practical checklist lives in how to secure an AI agent.

Bottom line

The PaperCut campaign opened no new vulnerabilities and showed no exotic tech. It showed something else: the barrier to mass attack has collapsed, and the speed jumped by an order of magnitude. You can still defend with the same tools — fast patching, a hidden perimeter, continuous testing and a ready response plan — but now you have to do it at machine tempo, not human tempo. The attackers already automated. If your own agents still run without guardrails, start there: read the top AI-agent vulnerabilities and put a firewall in front of them before someone else’s fleet of agents puts you on a list.

// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement