Agents
One operator ran hundreds of Codex- and DeepSeek-driven agents to compromise 440+ PaperCut servers at 395 organizations in 48 countries
GreyNoise and Blackpoint Cyber reported a suspected Russian-speaking actor who chained PaperCut MF/NG CVE-2026-81578 (auth bypass) and CVE-2026-82078 (RCE) using hundreds of AI agents built on OpenAI Codex and a DeepSeek model, alongside Mimikatz, SharpHound, Certipy and Rubeus. The actor first rehearsed against a lab replica with Active Directory. Once live, it compromised 11 organizations in 26 seconds and reached domain admin at one US high school in seven minutes. Education accounts for 204 of the victims. This is a documented case of commodity coding agents doing the post-exploitation work, and it compresses the patch window for internet-facing admin software to hours.
Source
↳ Follow the thread