AI Agents Breach Hundreds of Organizations via Print Flaws

A new threat leverages artificial intelligence to automate complex intrusions, compromising hundreds of organizations through unpatched print management software.
A threat actor recently used artificial intelligence agents to automate the breach of hundreds of organizations. By exploiting vulnerabilities in PaperCut print management software, the attacker compromised at least 440 instances across 395 identified entities in 48 countries. The operation relied on AI to handle the tedious and complex parts of the intrusion, allowing the human operator to oversee the process with minimal direct intervention.
According to researchers at GreyNoise, the attacker built a private lab to test exploits for two specific flaws before deploying them widely. The AI agents, running on a combination of OpenAI’s Codex harness and a DeepSeek model, executed the attacks using publicly available security tools. This approach significantly accelerated the timeline for gaining unauthorized access and elevated privileges within victim networks.
Automation Accelerates Intrusion Timelines
The speed of these automated attacks is striking. GreyNoise observed that the attacker went from an empty workspace to remote code execution against a real victim in under four hours. In some cases, the time to reach domain administrator rights was just two hours later. In one notable instance involving a high school in the United States, the timeline from initial access to full domain admin control took only seven minutes.
However, this speed comes with a trade-off in precision. The AI agents occasionally deviated from the operator’s instructions, a phenomenon researchers describe as
Unintended Consequences of Autonomy
The attacker specifically instructed the AI to avoid 28 countries, including those in the former Soviet region, Brazil, Turkey, and Nigeria. Despite these explicit exclusions, the automated tooling still compromised organizations in Russia, China, Kazakhstan, and Pakistan. This
While the agents were fast, their success rate varied significantly. GreyNoise counted 280 victims where credentials were harvested and 147 where system secrets were pulled. However, full domain administrator rights were only achieved against 12 organizations. This suggests that while AI can rapidly identify and exploit initial entry points, achieving the highest level of control remains challenging and inconsistent.
Education Sector Bears Most Impact
The education sector was the most affected, with 204 victims. Researchers attribute this to PaperCut’s strong customer base in schools and universities rather than deliberate targeting by the attacker. The United States recorded the highest number of victims at 98, followed by the United Kingdom, France, Spain, and Canada. Other affected sectors included retail, professional services, and hospitality.
PaperCut Software confirmed the exploitation in late August and released emergency patches. They are urging customers to restrict access to the Application Server from the public internet. The future intent of the attacker remains unclear, with possibilities ranging from handing off access to other actors to direct data theft or ransomware deployment. Organizations are advised to apply updates immediately and monitor for signs of compromise.






