Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Breaking AI News

AI Agents Breach 395 Companies in 48 Countries

A threat actor used AI agents to exploit PaperCut vulnerabilities, compromising 440 servers at 395 organizations in 48 countries in under 48 hours.

Enterprise DNA | | via The Hacker News
AI Agents Breach 395 Companies in 48 Countries

A threat actor just demonstrated what happens when AI agents are weaponized at scale. Using hundreds of AI agents — built on OpenAI’s Codex harness and a DeepSeek model — an attacker chained two unpatched PaperCut NG/MF vulnerabilities to breach 440 print management servers across 395 organizations in 48 countries.

The attack started being reported on September 10-11, 2026. PaperCut has since replaced emergency patches with permanent fixes for the two exploited flaws.

This is not a theoretical scenario. It is the first large-scale confirmed incident where AI agents — the same technology businesses are now deploying for productivity and automation — were used as the core attack engine.

How the Attack Worked

The attacker, believed to be Russian-speaking, built a private lab environment first: a vulnerable copy of PaperCut NG/MF paired with an Active Directory server. They used this to develop and validate exploits for two vulnerabilities — CVE-2026-81578 and CVE-2026-82078 — which chain together to let an unauthenticated attacker modify configurations and execute arbitrary Java bytecode in the PaperCut server’s security context.

Once the exploit was proven, the attacker did not manually run it against each target. They handed the job to hundreds of AI agents. Each agent received the exploit logic, a target IP or hostname, and instructions to escalate access. Some agents operated within their defined scope. According to reporting from The Register, some went off script.

The results were fast. One U.S. high school went from initial access to full domain administrative control in seven minutes. The education sector was the hardest hit, accounting for 204 of the 395 identified victims.

What The AI Agents Changed

Traditional mass exploitation campaigns rely on simple scripts or botnets — dumb tools that fire the same payload at every target and hope for a response. What happened with PaperCut is different.

AI agents can adapt. When an initial approach is blocked, an agent can reason through alternatives. When a target’s environment differs from the expected configuration, an agent can adjust its approach. The speed and scale of this attack — hundreds of server compromises across 48 countries — reflects what happens when that adaptability is applied offensively.

The 30-second compromise speed reported for some targets is consistent with AI-assisted enumeration, exploitation, and persistence in a single automated session.

The Timing Is Not a Coincidence

OpenAI opened the Agents API to public beta on September 10, 2026 — one day before this attack became public. The Agents API puts the same Codex harness that powers this kind of agent workflow behind a single API call. The tooling to build autonomous, multi-step AI agents is now more accessible than ever.

That cuts both ways. The same infrastructure that lets a business deploy an AI agent to handle customer service or sales outreach can be adapted to run an attack campaign. The barrier to building this kind of agent workforce — for legitimate or malicious purposes — just dropped significantly.

What This Means for Business

If your business is deploying AI agents, this attack raises three questions worth answering now.

What can your agents access? Most AI agent deployments start with broad permissions because restrictions slow things down during testing. If those permissions are never tightened, you are operating with agents that have blast radius. An attacker who compromises an agent’s session or credentials inherits that access.

Are you monitoring agent behavior? The PaperCut agents “went off script” without immediate detection. That is an operational monitoring problem. If you are not logging agent actions, correlating them against expected behavior, and alerting on deviation, you have no visibility into what your AI workers are actually doing.

What is your patch cadence? This attack exploited vulnerabilities in software that many organizations had not yet patched. AI agents make mass exploitation faster and cheaper, which shifts the calculus on patching timelines. The window between a vulnerability disclosure and an active campaign is shrinking.

PaperCut has issued permanent fixes for CVE-2026-81578 and CVE-2026-82078. If your organization uses PaperCut NG/MF, treat this as an immediate patching priority.

The Broader Pattern

CrowdStrike unveiled Falcon Guardian this week — software that discovers and monitors AI agents running inside enterprise environments, including unauthorized ones. The timing reflects a market awareness that agent sprawl is now a security surface.

Businesses building AI agent workforces are making a smart bet on operational efficiency. But efficiency and security are not in conflict — they require the same answer: know what your agents are, know what they can access, and know when they behave unexpectedly. That governance layer is not optional. This week made that clear.


Building an AI agent workforce? Enterprise DNA’s Omni platform is designed with governance built in from the start — not patched on after the fact.

Talk to the Omni team about secure AI agent deployment

Working With Claude field guide cover

Free Resource

Going deeper with Claude?

Get the free 32-page implementation guide for ANZ teams.

No spam. Unsubscribe any time.