
Eleven organizations hacked in twenty-six seconds. On August 31, 2026, a likely Russian-speaking attacker launched hundreds of AI agents (autonomous programs that chain actions together without a human stepping in at each stage) against PaperCut, a print management software widely used in schools. The report « Agents Gone Wild, » published on September 9, 2026 by GreyNoise, a threat intelligence company, details how these AI agents themselves developed, tested and launched the attacks against two flaws in the software. As of the report’s publication: 440 servers compromised, 395 organizations across 48 countries, including 31 in France.

What Happened on August 31, 2026
PaperCut is a print management software that lets an organization track, bill and administer its printing, copying and scanning jobs, in a cloud version or one installed on-site. It’s this second version, PaperCut NG and MF, that is the problem here. By default, it runs with maximum privileges (SYSTEM) on Windows and stays connected to the company’s Active Directory, the directory that manages every account on the network. Two flaws affect it, each identified by a CVE number, the public code assigned to every recorded vulnerability. The first, CVE-2026-81578, bypasses authentication. The second, CVE-2026-82078, allows remote code execution (RCE): the attacker then runs their own commands on the targeted machine, as if sitting right in front of it.
The GreyNoise report attributes the campaign to IP address 45.142.193.132, which has been monitored since early July 2026 for attacks against network equipment from several brands, including Palo Alto, Citrix and SonicWall. Before targeting a real victim, the attacker built a private lab with a vulnerable copy of PaperCut and an Active Directory server, to develop and test their exploits (programs designed to take advantage of a flaw and force entry into a system). At the same time, they built their target lists with Netlas.io, an internet scanning service, using an access key identified by researchers. The final tally comes to around 440 compromised PaperCut instances across 395 organizations, in 48 countries. GreyNoise notes that other real victims could not be linked to a named organization.
How AI Agents Did the Work
Once remote code execution was achieved and credentials harvested in his own lab, the attacker scaled up. He handed the rest of the job to hundreds of AI agents, driven by OpenAI’s Codex harness, the software shell that gives an artificial intelligence model the ability to act on its own, read data and execute code. Alongside this harness came a DeepSeek model instead of an in-house one, plus publicly available attack tools. OpenAI bears no direct responsibility for the campaign: Codex is just one tool among others here, on the same footing as DeepSeek. The AI agents search for, test and exploit PaperCut servers exposed on the internet on their own.

The speed measured by GreyNoise sums up the shift. The attacker starts from an empty workspace and gets their first code execution on a real victim in just under four hours. Two hours later, they land their first domain admin access (an account that controls every computer and user connected to the same corporate network). Once the campaign is fully underway, at least eleven organizations fall in twenty-six seconds. At an American high school, the initial access leads to full privileges in seven minutes, a figure cited by both GreyNoise and The Register. Across the whole campaign, GreyNoise measures a minimum time of five minutes and a maximum of 144 minutes, sometimes with several days of waiting between the two stages, due to the attacker’s inaction.
PaperCut did not leave the situation unanswered. On August 28, 2026, the vendor released emergency patches for both flaws, saying it was aware of confirmed incidents at customer sites. Its CEO would later clarify that the first reported compromise dated back to August 27, at an organization in the education sector, the day before the patch. On September 10, PaperCut released maintenance versions that replace those emergency patches.
The Countries and Sectors Hit Hardest
By far the hardest-hit sector is education, with 204 organizations affected. Next comes a category of unclassified organizations, 51 victims, then trade and professional services, 38 victims. GreyNoise does not see this as deliberate targeting of schools, but rather a reflection of PaperCut’s customer base, which is deeply rooted in education.

By country, the United States has the most victims, 98, ahead of the United Kingdom, 59. France and Spain follow, tied with 31 organizations each, then Canada with 24. France thus ranks as the third most affected country in the world, in a campaign that targeted no specific target but hit every exposed and vulnerable PaperCut server.
Credential theft was broader than full takeover. GreyNoise recorded stolen credentials at 280 victims, a figure to weigh against the 395 organizations listed as compromised.
When AI Agents Went Rogue
Before launching his AI agents, the attacker had given them a list of 28 countries to spare, headed by Russia, China, Hong Kong, Thailand and Iran. The practice is common among cybercriminals from the post-Soviet region: sparing your own country and its neighbors buys a form of impunity with local authorities. It’s this very list that leads GreyNoise to describe the attacker as likely Russian-speaking.
Except that the instruction wasn’t always followed. Help Net Security reports that GreyNoise found victims in several of the countries meant to be spared, including Russia, China, Kazakhstan and Pakistan. GreyNoise itself admits it doesn’t know why its agents strayed from the instruction. This is the episode that gives the report its title: « Agents Gone Wild. » The Register sums up the scene in a few words: « some went off script. »
What This Speed Changes Going Forward
What this campaign changes most is the time between the discovery of a flaw and its mass exploitation. Between the emergency patches of August 28 and the launch of the large-scale campaign on August 31, only three days passed. GreyNoise puts it bluntly: despite the safeguards of the most advanced artificial intelligence models in the United States, attackers are already using various large language models to run intrusions on a global scale. The question of who oversees these tools is far from abstract, as shown by the ruling obtained by Anthropic against the Pentagon. The topic ties into the era of AGI raised around GPT-6 Astra, where a model’s offensive capabilities become a security criterion.
Not all classic defenses gave way. In at least one case, Cloudflare’s web application firewall stopped the attempt before it succeeded. « Fundamental hardening of environments still matters against AI-enabled threats, » GreyNoise reminds us, recommending that PaperCut be updated to the maintenance versions released on September 10 and that the indicators of compromise (the technical traces, addresses, files or behaviors that reveal whether a system has been affected) published on its GitHub repository be checked.
As for the attacker, they have not yet shown their final intentions. GreyNoise doesn’t know whether he plans to resell his access to other groups or exploit it himself for data theft or a ransom demand. Out of the 395 compromised organizations, his AI agents only reached the top, full domain admin rights, in twelve of them.




0 Commentaires
Aucun commentaire pour le moment. Soyez le premier à commenter !