Somewhere in a Russian-speaking corner of the internet, someone built themselves a team of AI agents, pointed them at a print management server, and went to make coffee. By the time it was ready, eleven organizations had already been compromised — in 26 seconds.
440 Servers, 4 Hours, Zero Human Hands on the Keyboard
Security researchers say a threat actor wired together OpenAI's Codex harness, a DeepSeek model, and off-the-shelf offensive-security tools into an autonomous exploitation pipeline. The agents built a private lab to test two PaperCut NG/MF vulnerabilities (CVE-2026-81578 and CVE-2026-82078), then went hunting for real targets using the Netlas scanning platform.
The numbers are the kind that make sysadmins reach for the antacids: remote code execution in under four hours, domain admin access in six, and one U.S. high school fully pwned in seven minutes flat. By the time the dust settled, 440 PaperCut instances across 395 organizations in 48 countries had been hit, with education taking the hardest punch — roughly half of all victims.
The Attack Surface Just Learned to Work Overtime
This isn't "AI wrote some phishing emails." This is AI agents autonomously building, testing, and refining exploits against real infrastructure, at a speed and scale no human red team could match on their lunch break. The scary part isn't the sophistication — PaperCut's flaws were already known — it's the velocity.
Most breach timelines used to be measured in days or weeks of dwell time before anyone noticed. Here, credentials were harvested from 280 victims and admin privileges landed at a dozen organizations before most IT teams had finished their morning standup. Patch cadence just went from "get to it this sprint" to "get to it this hour."
The lesson isn't "don't use AI" — it's that your patching speed now has to outrun somebody else's AI, and that's a race most orgs aren't built for yet.
If your patch management still runs on a quarterly calendar instead of a threat feed, James and the WTK security team can help you build a defense posture that doesn't assume the bad guys are moving at human speed — grab our free supply-chain security checklist to start closing the gaps.
Source: BleepingComputer