Two PaperCut print-management vulnerabilities went from disclosure to patch in a single day in late August. That should have been the end of the story. Instead, threat intelligence firm GreyNoise reported this month that a single attacker used hundreds of AI agents, built on commercial models from OpenAI and DeepSeek, to compromise 395 organizations across 48 countries before most of them had a chance to apply the fix.
The campaign is one of the clearest public examples yet of what security researchers have been warning about for two years: AI doesn't just help attackers write exploits, it compresses the entire timeline from vulnerability to mass compromise down to hours.
The Vulnerability Chain
Two flaws in PaperCut NG/MF, self-hosted print management software widely used by schools, universities, and other organizations, were disclosed as zero-days on August 27 and patched the next day. CVE-2026-81578 (CVSS 8.8) is an improper access control flaw: The software's web management interface triggers administrative functions before authentication validation completes, letting an unauthenticated attacker remotely modify system configuration. On its own, that's a serious but contained configuration-tampering bug.
Chained with CVE-2026-82078 (CVSS 9.4), an unsafe dynamic class-loading flaw that lets arbitrary Java bytecode execute under the server's own security context, the combination produces full, unauthenticated remote code execution running as SYSTEM. PaperCut's later investigation found the actual attack combined the authentication bypass with database-driver behavior and arbitrary file-writing to achieve that execution in practice.
What AI Changed About the Timeline
GreyNoise attributes the campaign to a likely Russian-speaking threat actor who built, tested, and deployed exploits within days of the emergency patch, using AI agents powered by OpenAI's Codex and a DeepSeek model to do the engineering work that would previously have required a skilled team.
The scale matched the speed. GreyNoise found 440 PaperCut deployments compromised at 395 distinct organizations, with credentials harvested from 280 hosts. Blackpoint Cyber's parallel research described the tooling as hundreds of coordinated AI agents rather than a single script, used to develop, troubleshoot, and scale the attack across targets simultaneously.
The attacker reportedly tried to steer clear of targets in 28 specific countries, an operational-security habit common among certain threat actors. GreyNoise's findings note that restraint didn't hold consistently, some organizations in those excluded countries were compromised anyway.
Why the Victims Skewed Toward Schools
PaperCut's customer base leans heavily toward education, libraries, and other budget-constrained institutions managing shared printing across many users, exactly the kind of organization least likely to have a dedicated security team monitoring for a zero-day patched over a holiday weekend. That combination, a widely deployed niche product with a thin security bench behind it, is what let the campaign reach hundreds of victims before broad awareness of the exploit caught up.
PaperCut has since replaced its original emergency patches with a full maintenance release, published September 11, that the vendor says has been through standard release testing rather than rushed out under incident pressure.
What This Means for Your Patch Cycle
- Treat any zero-day affecting internet-facing infrastructure, print servers included, as a same-day patching priority. The old assumption that attackers need days or weeks to weaponize a disclosed flaw no longer holds when AI agents are doing the engineering.
- If your organization runs PaperCut NG/MF, confirm you're on the September 11 maintenance release, not still running one of the original emergency patches from late August.
- Don't assume a niche or unglamorous piece of infrastructure is a low priority for attackers. Print management software was exactly obscure enough to stay under-patched and exactly widespread enough to make a worthwhile target.
- If your security monitoring depends on human response times to unusual activity, this campaign is a useful benchmark: 26 seconds to compromise 11 organizations means detection has to be automated to matter at all.
Sources: AI Pulse · Where This Breaks · workplaceai.ai. GreyNoise's findings on the PaperCut campaign, published September 9, 2026, as reported by BleepingComputer, SecurityWeek, TechTimes, and CloudLinkTech. Vulnerability chain and CVSS scoring: TechTimes, citing SOCPrime's technical analysis, and CISA's Known Exploited Vulnerabilities catalog. AI agent tooling details: Blackpoint Cyber research as reported by HackRead. Patch timeline: The Hacker News, September 11, 2026. Every figure above is attributed to its original reporting; none is a WorkplaceAI study.