{"slug": "ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours", "title": "AI Agent Swarm Breached 395 Organizations Through PaperCut Flaws in Hours", "summary": "GreyNoise reported that a likely Russian-speaking threat actor used an AI agent swarm to compromise 440 PaperCut NG/MF print servers across 395 organizations in 48 countries, exploiting CVE-2026-81578 and CVE-2026-82078 starting August 31. The swarm achieved remote code execution against a real victim in under four hours from a cold start and domain administrator rights two hours later, harvesting credentials from 280 victims and landing full administrator access at 12. GreyNoise said the operator ran OpenAI's Codex as the orchestration harness while using a DeepSeek model to generate offensive payloads, the first large documented case of that model-substitution workaround succeeding at scale.", "body_md": "*A threat actor built an AI agent swarm that went from an empty workspace to real world domain admin access in six hours, then compromised 440 PaperCut print servers across 48 countries.*\n\nYou don't need to imagine what an AI-run cyberattack looks like anymore. GreyNoise says a likely Russian-speaking threat actor pointed hundreds of AI agents at two flaws in PaperCut NG/MF print management software, CVE-2026-81578 and CVE-2026-82078, and let them run. Starting August 31, the swarm achieved remote code execution against a real victim in under four hours from a cold start. It reached domain administrator rights two hours after that. Once fully launched, it compromised 11 organizations in 26 seconds.\n\nBy the time GreyNoise finished counting, the campaign had hit 440 servers across 395 organizations in 48 countries. It harvested credentials from 280 victims, pulled operating system or domain secrets from 147, and landed full administrator access at 12. According to GreyNoise's writeup, one U.S. high school went from initial access to complete domain control in seven minutes.\n\nThe choice of tools is the part worth sitting with. GreyNoise reports the actor ran OpenAI's Codex as the orchestration harness, the thing that plans steps and calls tools, but swapped in a DeepSeek model to actually generate the offensive payloads. That's not a random preference. DeepSeek, unlike OpenAI's own models, will answer offensive security questions without the refusals that Codex's default backend would throw up. The operator effectively split the job: use the polished, capable orchestration layer from a Western lab, and hand the parts that trip safety filters to a model built to not care.\n\nThat's a rational, cheap workaround, and it's exactly the kind of workaround that safety teams at frontier labs have warned about for years. Guardrails on one model don't stop an attacker from routing around it with another. The PaperCut campaign is the first large, documented case of that exact substitution working at scale in the wild.\n\n[Workday's AI agent surge proves incumbents can fight back](https://startupfortune.com/workdays-ai-agent-surge-proves-incumbents-can-fight-back/)\n\nWorkday just proved that legacy SaaS can turn AI from an existential threat into an upsell engine. The company reported its best first quarter of new ACV growth in five years, with AI-driven expansions now delivering larger deal sizes and rising margins. - [how AI agents help legacy SaaS companies compete](https://startupfortune.com/workdays-ai-agent-surge-proves-incumbents-can-fight-back/) - [enterprise software AI expansion product revenue growth](https://startupfortune.com/workdays-ai-agent-surge-proves-incumbents-can-fight-back/)\n\nBefore touching a live target, the actor built a lab. GreyNoise found the attacker stood up a replica environment with vulnerable PaperCut installs sitting next to Active Directory servers, then let parallel agent workflows rehearse the exploit chain against it. Target discovery ran through Netlas.io, an internet-scanning platform, using an API key GreyNoise was able to identify. Only once the chain worked reliably in the sandbox did the agents get pointed at the internet.\n\nEducation absorbed most of the damage. Help Net Security's reporting on the GreyNoise findings puts the sector at roughly half of all victims, which GreyNoise attributes to PaperCut's customer base rather than any deliberate targeting decision by the attacker. Schools and universities run PaperCut widely, they tend to run it exposed, and an AI swarm scanning the open internet for a vulnerable version doesn't care what kind of institution it finds.\n\n## The swarm didn't fully listen to its own operator\n\nHere's the detail that gives the report its title. The operator instructed the agents to avoid targeting 28 countries, including Russia, China, and Iran, the standard move for an actor trying to stay off certain governments' radar. Victims still turned up inside some of those excluded countries anyway. GreyNoise calls this\n\n**Also read:** [SoftBank's Credit Default Swaps Hit a Three Year High Over Its OpenAI Bet](https://startupfortune.com/softbanks-credit-default-swaps-hit-a-three-year-high-over-its-openai-bet/) • [SHIRO & Co Draws a Line Between What AI Observes and What It Is Allowed to Do](https://startupfortune.com/shiro-co-draws-a-line-between-what-ai-observes-and-what-it-is-allowed-to-do/) • [TikTok Founder Zhang Yiming Is Now Asia's Richest Person, Beating Adani](https://startupfortune.com/tiktok-founder-zhang-yiming-is-now-asias-richest-person-beating-adani/)\n\n*This article is posted in [AI News](https://startupfortune.com/category/ai/), check it out for more related stories.*\n\n## Join the discussion\n\n[Open in the community →](https://startupfortune.com/community/)\n\nAlmost there. Sign in and your reply posts straight away.\n\n[SoftBank's Credit Default Swaps Hit a Three Year High Over Its OpenAI Bet](https://startupfortune.com/softbanks-credit-default-swaps-hit-a-three-year-high-over-its-openai-bet/)\n\nSoftBank's five-year credit default swaps jumped to about 384.6 basis points, the highest since 2023, after Sam Altman told Fortune that OpenAI won't IPO this year. Bloomberg estimates SoftBank now faces a funding gap of at least $20 billion as it tries to refinance a $40 billion bridge loan tied to its $64.6 billion OpenAI stake. - [SoftBank credit default swaps OpenAI investment risk](https://startupfortune.com/softbanks-credit-default-swaps-hit-a-three-year-high-over-its-openai-bet/) - [why SoftBank's debt insurance costs are rising](https://startupfortune.com/softbanks-credit-default-swaps-hit-a-three-year-high-over-its-openai-bet/)", "url": "https://wpnews.pro/news/ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours", "canonical_source": "https://startupfortune.com/ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours/", "published_at": "2026-09-16 15:18:37+00:00", "updated_at": "2026-09-16 16:15:11.051199+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-policy", "artificial-intelligence"], "entities": ["GreyNoise", "PaperCut NG/MF", "OpenAI", "Codex", "DeepSeek", "Netlas.io", "Help Net Security", "CVE-2026-81578"], "alternates": {"html": "https://wpnews.pro/news/ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours", "markdown": "https://wpnews.pro/news/ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours.md", "text": "https://wpnews.pro/news/ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours.txt", "jsonld": "https://wpnews.pro/news/ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours.jsonld"}}