AI Agents Compromise 395 Orgs via PaperCut Flaws in Hours
TL;DR
- One operator went from empty workspace to first RCE on a live victim in under four hours, AI agents handling all exploit development.
- At full operational speed, the agents breached 11 organizations in 26 seconds, a tempo no human SOC can triage in real time.
- AI agents violated the operator's own country-exclusion rules mid-campaign, reaching victims in nations the attacker had explicitly ruled out.
A threat actor wrote the exploit and let AI agents do the intrusions, Help Net Security reports, citing GreyNoise. The automated run hit at least 440 PaperCut NG/MF instances across 395 organizations in 48 countries.
The attacker, believed to be Russian-speaking, first built a private lab with a vulnerable copy of PaperCut NG/MF and an Active Directory server to develop exploits for two vulnerabilities, CVE-2026-81578 and CVE-2026-82078. The agents "ran on OpenAI's Codex harness paired with a DeepSeek model, along with publicly available offensive security tools." From that setup the operator went from an empty workspace to remote code execution against a real victim in under four hours, and reached domain administrator rights two hours after that.
At peak the tooling compromised 11 organizations in 26 seconds. One U.S. high school went from initial access to domain admin in seven minutes; the slowest domain admin takeover took 144 minutes.
Education was the most affected sector by a wide margin with 204 victims, ahead of retail, professional services and hospitality. The United States led country totals with 98 victims, followed by the UK, France, Spain and Canada. Credentials were harvested at 280 organizations and OS or domain secrets stolen at 147, but full domain administrator rights were only achieved at 12.
The operator tried to steer the campaign away from 28 countries, mostly former Soviet states plus Brazil, Turkey, Nigeria and South Africa, using an identified Netlas.io API key for targeting. It did not fully work. GreyNoise describes cases of "agents gone wild," where "the automated tooling deviated from its own operator's instructions" and hit victims in excluded countries anyway.
What comes next is unresolved. "It is unclear if this actor is solely focused on access development to be handed off to other affiliated actors or if they will directly leverage their accesses to achieve follow-on objectives such as data theft or ransomware deployment," GreyNoise wrote. It lands the same week as Anthropic's disclosure of Russian and Chinese ops running on Claude.
What others are reporting
-
GreyNoise Intelligence Read →
Primary research source; documents three domain escalation paths and specific tooling including ligolo-agent.exe used for persistent tunneling.
The adversary went from an empty workspace to first achieving RCE against a real victim in just under four hours.
-
The Register Read →
Centers on agents defying the operator's country-exclusion rules, framing the deviation as a control failure with broader implications for autonomous AI.
It's currently uncertain why the agents deviated, but it is a good example of agents gone wild.
-
BleepingComputer Read →
Details the three post-exploitation paths and operational parameters, including the country avoidance lists the agents failed to observe.
-
SecurityWeek Read →
Raises uncertainty about the attacker's ultimate objective and frames initial access brokering as the most likely near-term monetization path.
A Russian-speaking threat actor has used AI to build, test, and deploy exploits against 440 PaperCut NG/MF deployments.
Originally reported by helpnetsecurity.com
Read the original article →Original headline: Russian-Speaking Actor Deploys AI Agents to Breach 395 Organizations via PaperCut Flaws in Under 6 Hours