A single operator used hundreds of AI agents to exploit two PaperCut flaws and breached 395 organizations across 48 countries in days. The story is not a new bug. It is how fast the old ones now get used.
- GreyNoise and Blackpoint reported the campaign on September 10, 2026. The target was PaperCut NG and MF print management software.
- Two chained flaws did the work. CVE-2026-81578 is an authentication bypass, CVE-2026-82078 is an unsafe reflection flaw that reaches remote code execution. PaperCut patched both on August 27 and 28.
- The agents ran on an OpenAI Codex harness with a DeepSeek model, plus commodity tools like Mimikatz and Impacket. Blackpoint found a persistent memory layer and an agent coordination interface in the exposed directory.
- Reported footprint. At least 440 servers, credentials from 280 victims, domain secrets from 147, and full domain administrator access at 12. Education took about half the hits.
- The timeline collapsed. Under four hours from an empty workspace to working remote code execution, the first domain admin two hours after that, and 11 organizations breached in 26 seconds.
The lesson for defenders is a patching problem. For internet facing administrative software, the window between disclosure and mass exploitation is now hours, not weeks.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.
