Fetching from the wire…
Public story · 2026-09-12 · high
GreyNoise traced a Codex-driven DeepSeek agent chaining two PaperCut CVEs to domain admin in as little as seven minutes.
Why now: GreyNoise published the campaign breakdown on September 11.
A Russian-speaking actor ran OpenAI's Codex harness against a DeepSeek model to chain two PaperCut NG/MF vulnerabilities, CVE-2026-81578 and CVE-2026-82078, into a campaign that hit at least 440 instances across 395 organizations in 48 countries. GreyNoise tracked the intrusions and found remote code execution landing in under four hours, with domain admin access following about two hours after that, per Help Net Security's writeup.
The speed is what stands out. Eleven organizations were compromised in 26 seconds. One US high school went from initial access to full domain admin in seven minutes. Education took the heaviest hit, with 204 of the 395 victim organizations in that sector, likely reflecting how widely PaperCut print management sits inside school districts.
What makes this different from a scripted exploit chain is the orchestration layer. Codex is the same agent harness developers use to automate coding tasks, here directing a DeepSeek model alongside off-the-shelf offensive tooling to work through targets. Nobody had to babysit each step. The agent found a vulnerable instance, exploited it, escalated, and moved to the next target on its own timeline, not an operator's.
Security teams building their own agent-assisted detection pipelines now face the same speed on the other side. An unpatched PaperCut instance with a public-facing web interface is a machine-speed problem, not a business-hours one. Help Net Security's report doesn't say whether GreyNoise identified a specific patch gap or misconfiguration common to the 440 compromised instances, which matters if defenders want to know exactly what to check first.
Each link below shares sources, entities, or timing with this story.
GreyNoise and Blackpoint Cyber tracked a suspected Russian-speaking operator who chained two PaperCut MF/NG bugs, the auth bypass CVE-2026-81578 and the RCE CVE-2026-82078. The actor first rehearsed against a lab copy with Active Directory. Once live, it compromised 11 organiz...
Unit 42 documented an operator in Zhuhai driving the Hermes Agent framework over Telegram with DeepSeek as the reasoning engine, selecting targets and changing tactics after failures. Confirmed impact was narrow: three Citrix NetScaler memory-exfiltration compromises (CVE-2026...
GPT-5.6 Luna went to $0.20 input / $1.20 output per million tokens on July 30. That's an 80% cut. Terra dropped 20%. Luna's input now undercuts Gemini 3.1 Flash-Lite ($0.25/$1.50) and sits at one-fifth of Claude Haiku 4.5's $1 input. Simon Willison covered the announcement and...
Thibault Sottiaux at OpenAI published an investigation into "a handful of reports where GPT-5.6 unexpectedly deleted files," finding it happens most commonly when full access mode is enabled in Codex. Simon Willison relayed it. A frontier lab publishing a first-party post-mort...
$3,054 against $38,370. Same benchmark, better score. Praxist (arXiv 2608.25955, submitted August 26) replaces per-attempt agent memory with a typed evidence graph of findings, plus lane-structured frontiers and agendas, so later attempts inherit validated mechanisms rather th...
The July 18 release notes bundle fixes that restore the full window, which means it had been silently degraded for some unspecified period. If you benchmarked those models in Codex over the past few weeks and found long-context performance underwhelming, you may have been meas...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.