A real-world cyber campaign used hundreds of AI agents to help develop, test and scale attacks against PaperCut systems — showing how one operator can now automate work that once required far more manual effort.
WHAT’S HAPPENING
GreyNoise says a likely Russian-speaking threat actor used hundreds of AI agents alongside offensive-security tools to exploit vulnerabilities in PaperCut NG/MF.
The campaign compromised at least 440 PaperCut instances across 395 identified organizations in 48 countries. (greynoise.io)
The attack chained two actively exploited flaws:
CVE-2026-81578, an authentication-bypass vulnerability, and CVE-2026-82078, which can enable remote code execution when combined with the first flaw. (arcticwolf.com)
WHY IT MATTERS
This was not simply a hacker asking an AI chatbot to write malicious code.
GreyNoise says the operator used AI agents to help:
develop exploits, build target lists, test attacks, retry failures and scale the campaign across many systems at once.
The attacker moved from an empty workspace to remote code execution against a real victim in under four hours.
Once the campaign was fully running, at least 11 organizations were compromised in 26 seconds. (greynoise.io)
WHO BENEFITS
Attackers can potentially move faster, test more targets and automate repetitive parts of cyber operations.
A single operator may be able to coordinate far more activity than before.
WHO LOSES
Organizations running exposed or unpatched systems face greater pressure when attackers can scale exploitation faster.
Education was hit especially hard in this campaign, with GreyNoise identifying 204 affected education-sector victims among the compromised instances. (greynoise.io)
WHAT HAPPENS NEXT
The campaign still required human direction, and traditional defenses mattered. GreyNoise documented cases where normal hardening measures blocked the attack.
But the operating model is changing.
Cyberattacks may increasingly move from:
one attacker using one tool
to:
one operator directing a swarm of AI agents.
The bigger shift is not that AI invented cyberattacks.
It is that AI may allow attackers to run many more of them, much faster.
.