NewsTradingSentimentCalendarCommunityBriefing
Tech

AI Agents Drive Mass PaperCut Breaches

By Tech Desk · 2026-09-10 · 3 min read
A digital network of interconnected nodes forming a complex web structure
Illustration: Tradingbird

A suspected Russian-speaking threat actor used automated AI agents to exploit security flaws in PaperCut software, compromising over 440 instances across 48 countries in a matter of hours.

A suspected Russian-speaking cyber actor has successfully breached more than 440 instances of PaperCut NG/MF software by leveraging artificial intelligence to accelerate exploit development. The attack, which targeted organizations in 48 countries, marks a significant shift in how threat actors operate, moving from manual reconnaissance to automated, large-scale intrusion campaigns. According to reports from The Hacker News, the activity originated from a single IP address that had been flagged for unauthorized port scanning and brute-force attempts in recent weeks.

The core of the attack relied on a combination of two recently disclosed security flaws, an authentication bypass and a remote code execution chain. While the initial vulnerability research and exploit building were done in a self-hosted lab environment, the actual compromise phase was executed using hundreds of AI agents. These agents, powered by models from OpenAI and DeepSeek, worked in parallel to identify targets, execute exploits, and harvest credentials, drastically reducing the time needed to gain full control over victim systems.

Automated Exploitation at Scale

Threat intelligence firm GreyNoise noted that the attacker progressed from an empty workspace to achieving remote code execution against a real victim in just under four hours. Once the campaign began in earnest, the actor compromised at least 11 organizations in 26 seconds. This speed was enabled by the use of offensive security tools like Mimikatz and SharpHound, which were orchestrated by AI agents to identify hosts, users, and sensitive configuration data. The automation allowed the actor to manage multiple attack workflows simultaneously, a capability that would be difficult to replicate manually.

The trade-off for this speed was a lack of precision in target selection. Although the actor attempted to avoid targeting entities in 28 specific countries, including Russia and China, the automated nature of the attack led to accidental intrusions in these regions. This suggests that while AI agents can process vast amounts of data quickly, they may lack the nuanced decision-making required to strictly adhere to complex exclusion lists. The result was a broader victimology than initially intended, with organizations in education sectors across the U.S., U.K., and Europe being primary targets.

Unclear End Goals and Risks

The ultimate objective of the attacker remains unclear. GreyNoise stated that it is uncertain whether the actor is focused on developing access to be handed off to other affiliates or if they intend to directly leverage these accesses for data theft or ransomware deployment. In one notable incident involving a U.S. high school, the duration between initial access and full domain administrator access was a mere seven minutes. This rapid escalation highlights the potential danger of AI-assisted attacks, where the window for defenders to react is significantly compressed.

Blackpoint Cyber, which also tracked the activity, traced the workflow back to exposed operator infrastructure. This infrastructure depicted the AI-assisted process from vulnerability research to execution, including target filtering, failure analysis, and repeated retry waves. The use of AI to automate these stages demonstrates a new level of operational efficiency for threat actors, raising concerns about the future landscape of cyber threats. As AI models become more capable of integrating agentic capabilities into various stages of the attack lifecycle, the risk of large-scale, automated breaches is likely to increase.

Implications for Defenders

For organizations, this incident underscores the importance of patching vulnerabilities in internet-facing software like PaperCut. The attacker’s success was largely due to the exploitation of known flaws that had not been patched in time. Defenders must ensure that their systems are up to date and that they have robust monitoring capabilities to detect and respond to automated attack patterns. The speed and scale of AI-driven attacks require a corresponding level of automation in defense strategies to keep pace with the evolving threat landscape.

The use of AI in cyber attacks is not a new phenomenon, but the integration of agentic capabilities into the attack lifecycle represents a significant evolution. As threat actors continue to leverage AI to accelerate and conduct attacks at scale, the burden on defenders to adapt and innovate will only grow. The PaperCut breach serves as a stark reminder of the potential consequences of slow patching and inadequate monitoring in an era of automated threats.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories