Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

Hackers Used Hundreds of AI Agents to Breach 395 Organizations in Under a Day

What Happened

A suspected Russian-speaking threat actor built and ran an exploitation campaign against PaperCut NG and MF print-management servers largely through autonomous AI agents. Starting August 31, the operator combined OpenAI’s Codex and DeepSeek models with commodity offensive tools to write, test, and refine exploit code for two chainable PaperCut vulnerabilities, CVE-2026-81578 and CVE-2026-82078, together enabling authentication bypass and unauthorized configuration changes leading to remote code execution. Researchers at GreyNoise, who tracked the campaign, report the actor moving from an empty operating environment to code execution on a live victim in under four hours, then obtaining its first domain administrator credentials roughly two hours later. The campaign compromised 440 PaperCut instances tied to 395 organizations across 48 countries, harvesting credentials from 280 victims and gaining administrator privileges at 12. Education-sector targets accounted for roughly half of all confirmed breaches. Full details are available from BleepingComputer.

Why This Matters for Canadian Organizations

PaperCut runs across Canadian school boards, universities, municipal governments, and hospital networks, managing print quotas and access on shared devices. Those environments tend to run lean IT teams and patch on longer cycles than enterprise networks, precisely the conditions this campaign exploited. The speed of the attack, hours rather than days from initial access to domain compromise, outpaces the response timelines most institutions plan around. This stands as a working, largely automated method for turning an unpatched print server into a foothold across an entire network, not a theoretical risk.

What to Do

Patch PaperCut NG and MF to the latest version immediately and confirm neither CVE-2026-81578 nor CVE-2026-82078 remains exploitable in your environment. Segment print-management servers away from domain controllers and other high-value systems, so a compromised PaperCut instance stops short of becoming a direct path to administrator credentials. Watch for anomalous authentication or configuration-change activity on PaperCut servers, since the automated nature of this campaign leaves short detection windows. Boards and IT leadership at education and municipal institutions should treat AI-accelerated exploitation as a planning assumption rather than a future risk. Technical analysis of the attack sequence is available from GreyNoise.

Enjoy this article? Don’t forget to share.