presentofai

AI agents exploit PaperCut systems at 395 orgs

TL;DR

A likely Russian-speaking threat actor deployed hundreds of AI agents powered by OpenAI Codex and DeepSeek to breach 440 PaperCut print-management systems at 395 organizations across 48 countries, demonstrating that LLM-assisted attacks can now operate at machine speed and global scale.

What happened

  • 395 organizations compromised across 48 countries, with 440 individual PaperCut NG/MF systems affected, per GreyNoise threat intelligence.
  • Attacker exploited two newly disclosed PaperCut vulnerabilities: one authentication bypass, one enabling remote-code execution; PaperCut issued emergency patches in late August and updated versions on Sept. 10.
  • Hundreds of AI agents were used as the attack engine, running OpenAI Codex as a harness alongside a DeepSeek model and publicly available offensive security tools.
  • 11 organizations were compromised within 26 seconds of campaign launch; the attacker achieved remote-code execution against the first victim in under four hours from a blank workspace.
  • Attacker used Netlas search service to build target lists and pre-tested exploits in a private lab with vulnerable PaperCut software and an Active Directory server.

Why it matters

  • LLMs collapsed the attacker timeline: tasks that once took days of manual effort, reconnaissance, exploit development, lateral movement, now happen in minutes at scale.
  • Domain administrator access obtained at 12 organizations; at one U.S. high school, full domain control was reached within seven minutes of initial entry, enabling credential harvesting across entire Windows domains.
  • 204 of 395 victims were education institutions, reflecting PaperCut's heavy footprint in that sector and signaling that under-resourced orgs face disproportionate exposure.
  • The attacker instructed agents to avoid 28 countries including Russia, Belarus, and China, a strong geopolitical fingerprint pointing to state-adjacent or Russian-speaking origin.
  • Cloudflare's WAF blocked at least one attack, showing that existing perimeter defenses can interrupt AI-driven campaigns but did not prevent the broader breach wave.

What to watch next

  • Patch adoption rate: organizations still running pre-Sept. 10 PaperCut versions remain exposed; watch for GreyNoise or CISA advisories tracking unpatched install counts.
  • Attribution confirmation: the 28-country avoidance list and lab tradecraft may yield enough forensic signal for a formal government attribution to a known Russian threat group.
  • Copycat campaigns: the attacker's Codex-plus-DeepSeek agent architecture is now documented publicly, lowering the bar for other actors to replicate the playbook against different enterprise software targets.

Originally published on Present of AI, a daily source-linked AI news timeline. Read the full timeline or browse the open dataset.