TechNewsReel
Live

AI Agents Compromise 395 PaperCut Organizations in Rapid-Fire Campaign

A sophisticated harness using OpenAI Codex and DeepSeek enabled an attacker to breach 11 targets in just 26 seconds.

TechNewsReel Newsroom · September 10, 2026

An attacker leveraged hundreds of AI agents to exploit vulnerabilities in PaperCut MF/NG, resulting in the compromise of at least 395 identified organizations. The campaign demonstrates a significant shift in the scale and speed of cyberattacks through the use of advanced automation.

According to threat intelligence from GreyNoise, the attacker utilized a sophisticated AI-driven harness combining OpenAI's Codex and a DeepSeek model to automate the intrusion process. The efficiency of this setup was stark: once the campaign was launched, the system successfully compromised 11 separate organizations in only 26 seconds. This level of rapid-fire exploitation allowed the attacker to hit hundreds of targets far faster than traditional manual or script-based methods would permit.

The shift to AI agents

Historically, large-scale vulnerability exploitation relied on static scripts or manual effort, which created a linear relationship between the attacker's time and the number of targets hit. The introduction of AI agents changes this dynamic by allowing the attack infrastructure to adapt and execute complex tasks autonomously. By integrating large language models (LLMs) into the exploit chain, attackers can now automate the reconnaissance and delivery phases of an attack across diverse network environments simultaneously.

Industry implications

This event signals a critical inflection point for enterprise security. The ability to compromise nearly 400 organizations using AI-driven automation suggests that the window for defenders to react to a newly disclosed vulnerability is shrinking toward zero. When an attacker can breach multiple networks in seconds, traditional patching cycles—which often take days or weeks—become insufficient. Security teams must now contend with "machine-speed" threats that can identify and exploit weaknesses across the global internet almost instantaneously.

Future outlook

As AI models become more accessible and capable, the industry expects a rise in similar automated campaigns. Security researchers are now monitoring whether these agents can be further tuned to bypass more complex detection systems or pivot within networks without human intervention. While the PaperCut incident provides a clear example of AI-driven scale, the full extent of the data exfiltrated from the 395 organizations remains a primary focus for ongoing forensic investigations.

Get a notification when a big story breaks. A few a day at most — no spam.