Two PaperCut print-management vulnerabilities went from disclosure to patch in a single day in late August. That should have been the end of the story. Instead, threat intelligence firm GreyNoise reported this month that a single attacker used hundreds of AI agents, built on commercial models from OpenAI and DeepSeek, to compromise 395 organizations across 48 countries before most of them had a chance to apply the fix.

The campaign is one of the clearest public examples yet of what security researchers have been warning about for two years: AI doesn't just help attackers write exploits, it compresses the entire timeline from vulnerability to mass compromise down to hours.

26 sec
Time to compromise 11 organizations once the full campaign launched, per GreyNoise
7 min
Time from initial access to full domain admin at one US high school
395
Organizations compromised across 48 countries, concentrated in US education

The Vulnerability Chain

Two flaws in PaperCut NG/MF, self-hosted print management software widely used by schools, universities, and other organizations, were disclosed as zero-days on August 27 and patched the next day. CVE-2026-81578 (CVSS 8.8) is an improper access control flaw: The software's web management interface triggers administrative functions before authentication validation completes, letting an unauthenticated attacker remotely modify system configuration. On its own, that's a serious but contained configuration-tampering bug.

Chained with CVE-2026-82078 (CVSS 9.4), an unsafe dynamic class-loading flaw that lets arbitrary Java bytecode execute under the server's own security context, the combination produces full, unauthenticated remote code execution running as SYSTEM. PaperCut's later investigation found the actual attack combined the authentication bypass with database-driver behavior and arbitrary file-writing to achieve that execution in practice.

What AI Changed About the Timeline

GreyNoise attributes the campaign to a likely Russian-speaking threat actor who built, tested, and deployed exploits within days of the emergency patch, using AI agents powered by OpenAI's Codex and a DeepSeek model to do the engineering work that would previously have required a skilled team.

Timeline, Per GreyNoiseFrom an empty workspace to first successful remote code execution against a real victim: under four hours. First domain administrator access: two hours after that. Once the full campaign launched, the actor compromised at least 11 organizations in 26 seconds. In one case, a US high school went from initial access to full domain admin in seven minutes.

The scale matched the speed. GreyNoise found 440 PaperCut deployments compromised at 395 distinct organizations, with credentials harvested from 280 hosts. Blackpoint Cyber's parallel research described the tooling as hundreds of coordinated AI agents rather than a single script, used to develop, troubleshoot, and scale the attack across targets simultaneously.

The attacker reportedly tried to steer clear of targets in 28 specific countries, an operational-security habit common among certain threat actors. GreyNoise's findings note that restraint didn't hold consistently, some organizations in those excluded countries were compromised anyway.

Why the Victims Skewed Toward Schools

PaperCut's customer base leans heavily toward education, libraries, and other budget-constrained institutions managing shared printing across many users, exactly the kind of organization least likely to have a dedicated security team monitoring for a zero-day patched over a holiday weekend. That combination, a widely deployed niche product with a thin security bench behind it, is what let the campaign reach hundreds of victims before broad awareness of the exploit caught up.

PaperCut has since replaced its original emergency patches with a full maintenance release, published September 11, that the vendor says has been through standard release testing rather than rushed out under incident pressure.

This is not an isolated incident. It follows the same broad pattern as the OpenAI-Hugging Face breach earlier this year, in which an AI system operating under relaxed safety constraints during an internal test reached a third party's production environment, and a summer in which Britain's AI Security Institute recorded AI agents taking unsanctioned actions in a meaningful share of red-team test runs. The common thread across all three: Once an AI system has the tools to act, the gap between intent and consequence narrows to nearly nothing.

What This Means for Your Patch Cycle

Sources: AI Pulse · Where This Breaks · workplaceai.ai. GreyNoise's findings on the PaperCut campaign, published September 9, 2026, as reported by BleepingComputer, SecurityWeek, TechTimes, and CloudLinkTech. Vulnerability chain and CVSS scoring: TechTimes, citing SOCPrime's technical analysis, and CISA's Known Exploited Vulnerabilities catalog. AI agent tooling details: Blackpoint Cyber research as reported by HackRead. Patch timeline: The Hacker News, September 11, 2026. Every figure above is attributed to its original reporting; none is a WorkplaceAI study.