Face-free Unsplash teal LED panel / circuit glow — cybersecurity infrastructure hero still for PaperCut NG/MF AI-orchestrated campaign September 2026

AI agents breached 395 orgs via PaperCut

From Mexico — Saturday I’m reading GreyNoise’s Agents Gone Wild write-up, with same-week echoes from The Hacker News and Help Net Security. A likely Russian-speaking actor used IP 45.142.193.132 plus AI to develop, test, and run exploits for PaperCut NG/MF — CVE-2026-81578 and CVE-2026-82078, an auth-bypass + RCE chain. I’m sticking to what those reports say.

PaperCut NG/MF is self-hosted Java print management. GreyNoise notes it often runs as SYSTEM on Windows and is frequently Active Directory–joined — which is why a print box can become a domain problem fast. Help Net Security also says PaperCut confirmed exploitation in late August and shipped emergency patches, urging customers to keep the Application Server off the public internet.

Hundreds of agents, not one clever human

After lab RCE and credential harvest, the actor unleashed hundreds of AI agents powered by OpenAI’s Codex (as the harness) plus a DeepSeek model — GreyNoise is explicit: not OpenAI models for the LLM — alongside public offensive tools like Mimikatz, SharpHound, Certipy, Rubeus, and Impacket. Result per GreyNoise: at least 440 PaperCut MF/NG instances at 395 identified organizations in 48 countries. The Hacker News and Blackpoint map the same campaign.

Speed is the part that sticks. Empty workspace → first real-victim RCE in under four hours; first domain admin about two hours later. Once the campaign launched, GreyNoise saw at least 11 organizations compromised in 26 seconds. One U.S. high school went from initial access to domain admin in seven minutes. Domain admin still landed at only 12 orgs total — fastest 5 minutes, slowest 144 where it happened.

Cream-paper schematic of PaperCut AI-orchestrated campaign September 2026: ≥440 instances / 395 orgs / 48 countries; Codex harness + DeepSeek; education 204 victims; domain admin at 12 orgs; under 4 hours to first real-victim RCE; 7 minutes to domain admin at a US high school
Agents Gone Wild stack from GreyNoise (+ THN / Help Net / Blackpoint) — schematic by Tech & AI Pulse.

Education hit hardest — and “agents gone wild”

Education accounts for 204 victims — GreyNoise ties that more to PaperCut’s customer base than deliberate sector targeting. By country: United States 98, then UK, France, Spain, Canada. The actor tried to avoid 28 countries (including Russia, China, Hong Kong, Thailand, Iran, Venezuela, Indonesia, Pakistan, Bangladesh), but observed victimology shows that restraint failed in some cases — hence the title Agents Gone Wild.

End goal is still unclear — access broker vs direct theft/ransomware. GreyNoise partnered with IR firms for victim notifications. One bright spot: Cloudflare’s WAF defeated at least one attempt. Blackpoint’s take, via THN, is that the strongest AI impact wasn’t a novel exploit technique — it was cutting the human effort across research → exploit → retry, with tools like Hindsight (agent memory) and AionUi (multi-agent GUI) in the loop. From Hermosillo, my takeaway is blunt: patch PaperCut, get it off the open internet, and remember basic hardening still works when agents are doing the clicking.

Primary: GreyNoise. Same-week: The Hacker News, Help Net Security, Blackpoint.