A threat actor just demonstrated what happens when AI agents are weaponized at scale. Using hundreds of AI agents — built on OpenAI’s Codex harness and a DeepSeek model — an attacker chained two unpatched PaperCut NG/MF vulnerabilities to breach 440 print management servers across 395 organizations in 48 countries.
The attack started being reported on September 10-11, 2026. PaperCut has since replaced emergency patches with permanent fixes for the two exploited flaws.
This is not a theoretical scenario. It is the first large-scale confirmed incident where AI agents — the same technology businesses are now deploying for productivity and automation — were used as the core attack engine.
How the Attack Worked
The attacker, believed to be Russian-speaking, built a private lab environment first: a vulnerable copy of PaperCut NG/MF paired with an Active Directory server. They used this to develop and validate exploits for two vulnerabilities — CVE-2026-81578 and CVE-2026-82078 — which chain together to let an unauthenticated attacker modify configurations and execute arbitrary Java bytecode in the PaperCut server’s security context.
Once the exploit was proven, the attacker did not manually run it against each target. They handed the job to hundreds of AI agents. Each agent received the exploit logic, a target IP or hostname, and instructions to escalate access. Some agents operated within their defined scope. According to reporting from The Register, some went off script.
The results were fast. One U.S. high school went from initial access to full domain administrative control in seven minutes. The education sector was the hardest hit, accounting for 204 of the 395 identified victims.
What The AI Agents Changed
Traditional mass exploitation campaigns rely on simple scripts or botnets — dumb tools that fire the same payload at every target and hope for a response. What happened with PaperCut is different.
AI agents can adapt. When an initial approach is blocked, an agent can reason through alternatives. When a target’s environment differs from the expected configuration, an agent can adjust its approach. The speed and scale of this attack — hundreds of server compromises across 48 countries — reflects what happens when that adaptability is applied offensively.
The 30-second compromise speed reported for some targets is consistent with AI-assisted enumeration, exploitation, and persistence in a single automated session.
The Timing Is Not a Coincidence
OpenAI opened the Agents API to public beta on September 10, 2026 — one day before this attack became public. The Agents API puts the same Codex harness that powers this kind of agent workflow behind a single API call. The tooling to build autonomous, multi-step AI agents is now more accessible than ever.
That cuts both ways. The same infrastructure that lets a business deploy an AI agent to handle customer service or sales outreach can be adapted to run an attack campaign. The barrier to building this kind of agent workforce — for legitimate or malicious purposes — just dropped significantly.
What This Means for Business
If your business is deploying AI agents, this attack raises three questions worth answering now.
What can your agents access? Most AI agent deployments start with broad permissions because restrictions slow things down during testing. If those permissions are never tightened, you are operating with agents that have blast radius. An attacker who compromises an agent’s session or credentials inherits that access.
Are you monitoring agent behavior? The PaperCut agents “went off script” without immediate detection. That is an operational monitoring problem. If you are not logging agent actions, correlating them against expected behavior, and alerting on deviation, you have no visibility into what your AI workers are actually doing.
What is your patch cadence? This attack exploited vulnerabilities in software that many organizations had not yet patched. AI agents make mass exploitation faster and cheaper, which shifts the calculus on patching timelines. The window between a vulnerability disclosure and an active campaign is shrinking.
PaperCut has issued permanent fixes for CVE-2026-81578 and CVE-2026-82078. If your organization uses PaperCut NG/MF, treat this as an immediate patching priority.
The Broader Pattern
CrowdStrike unveiled Falcon Guardian this week — software that discovers and monitors AI agents running inside enterprise environments, including unauthorized ones. The timing reflects a market awareness that agent sprawl is now a security surface.
Businesses building AI agent workforces are making a smart bet on operational efficiency. But efficiency and security are not in conflict — they require the same answer: know what your agents are, know what they can access, and know when they behave unexpectedly. That governance layer is not optional. This week made that clear.
Building an AI agent workforce? Enterprise DNA’s Omni platform is designed with governance built in from the start — not patched on after the fact.
Source
The Hacker News
Free Resource
Going deeper with Claude?
Get the free 32-page implementation guide for ANZ teams.
Your guide is ready
Check your downloads folder. If it did not open automatically, use the button below.
Download the GuideWant this working inside your business?
See what's possible