AI Agents Compromised 11 Organizations in 26 Seconds in PaperCut Campaign
Cybersecurity firm GreyNoise has detailed a large-scale attack campaign, launched August 31, 2026, in which a threat actor deployed hundreds of AI agents using OpenAI Codex and DeepSeek models to exploit two known PaperCut NG/MF vulnerabilities. The campaign ultimately compromised at least 440 PaperCut instances across 395 organizations in 48 countries, with attackers harvesting credentials, OS secrets, and full administrator privileges from dozens of victims. Roughly half of all affected organizations were schools or universities, with one high school losing full domain administrator access within seven minutes of initial intrusion. The attackers used established post-exploitation techniques — including LSASS memory dumping, the noPac Active Directory exploit, and DCSync — rather than any novel methods, with AI tooling dramatically compressing the time needed to build and execute the intrusion chain. The findings align with a broader trend documented by Google's Threat Intelligence Group, which separately confirmed a financially motivated actor used AI tools to conduct a mass credential-harvesting campaign against cloud infrastructure in under six hours.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in