Fetching from the wire…
Public story · 2026-09-11 · high
GreyNoise traced the campaign to a suspected Russian-speaking operator who breached 11 organizations in 26 seconds.
Why now: GreyNoise and Blackpoint Cyber's tracking of the campaign put the count at 440+ servers across 48 countries.
A suspected Russian-speaking operator chained two PaperCut flaws to compromise 440+ servers across 48 countries, per GreyNoise's account of the campaign.
GreyNoise tracked the campaign jointly with Blackpoint Cyber. The operator compromised 11 organizations in 26 seconds and reached domain admin at a US high school seven minutes later.
The operator rehearsed the full chain against a lab copy of Active Directory before going live.
The entry point was two bugs stacked together. CVE-2026-81578 is an authentication bypass; CVE-2026-82078 is a remote-code-execution flaw in PaperCut MF and NG. Chained, they let the operator skip credentials and run code straight on the admin server.
Getting in was only step one. Commodity coding agents built on Codex and DeepSeek handled what came after, running Mimikatz, SharpHound, Certipy and Rubeus to pull credentials and map Active Directory without a human doing the typing.
Schools account for 204 of the 440+ victims tracked in the campaign.
Each link below shares sources, entities, or timing with this story.
Unit 42 documented an operator in Zhuhai driving the Hermes Agent framework over Telegram with DeepSeek as the reasoning engine, selecting targets and changing tactics after failures. Confirmed impact was narrow: three Citrix NetScaler memory-exfiltration compromises (CVE-2026...
Warp released its client codebase under AGPL-3.0, surged to 56,000 GitHub stars and #2 on GitHub Trending. But the real story isn't the open-sourcing. It's the repositioning. Warp isn't calling itself a terminal anymore. It's an "agentic development environment." The product n...
A Chinese lab shipped a runtime that manages two American coding agents as subagents, and it went from repo creation to 145,439 stars in four days. deepseek-ai/deepseek-harness published dsh-v0.1.0-rc.7 at 12:01 UTC today, its first tagged release since the repo appeared on Au...
On Latent Space July 28, OpenAI core product engineering lead Akshay Nathan said Codex and ChatGPT Work combined reached 10 million users within two weeks of the July 9 launch, with monthly actives up more than 10x since January 2026. The number that should reframe your produc...
Show HN: the developer behind JUCE and Cmajor launched an open-source agent where sessions are Yjs-backed CRDT documents instead of chat logs, and nearly everything (context items, loop strategies, slash commands) is a forkable JavaScript plugin. Go plus Wails backend to dodge...
Posted to Show HN on September 4, it's a Rust loop engine that dispatches Claude, Codex, Hermes, Pi or NanoClaw against a codebase on a schedule, each run in a fresh isolated workbench inside a tmux session to prevent state leakage, with watchdog monitoring and REST, MCP and w...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.