All Insights

Hundreds of AI Agents Just Ransacked 395 Organizations Through Their Print Servers

CivSafe Team·September 11, 2026·5 min read

Your print server is probably the least-watched machine on your network. No one's logging into it daily, nobody's running EDR scans against it obsessively, and it's been quietly humming along doing its job for years. Which is exactly why a likely Russian-speaking attacker chose it as the entry point for one of the most automated cyberattack campaigns ever documented.

GreyNoise published the full breakdown yesterday. The short version: an attacker with two fresh PaperCut vulnerabilities and access to AI coding tools spun up hundreds of autonomous agents, pointed them at the internet, and compromised at least 440 PaperCut print servers across 395 organizations in 48 countries. The campaign ran largely on its own. The Register's headline says it best: some of the agents went off script.

If you're running PaperCut NG or MF and you haven't applied Emergency Patch Release 3, you need to stop reading and go do that first. CISA added these CVEs to the Known Exploited Vulnerabilities catalog on August 31 with a remediation deadline of September 14. That's this Sunday.

What actually happened

The attacker used two zero-days, CVE-2026-81578 (missing authentication, CVSS 9.4) and CVE-2026-82078 (unsafe Java class loading leading to RCE), chained together to get unauthenticated remote code execution on any exposed PaperCut application server.

But the part that matters for everyone tracking where AI threats are going: the attacker didn't sit at a keyboard and manually exploit each target. They built a private test lab, got the exploit working, then handed the actual attack to AI agents running OpenAI Codex and a DeepSeek model, alongside public offensive tooling — Mimikatz, SharpHound, Certipy, Rubeus, Impacket. The agents handled target discovery through Netlas.io, exploitation, credential harvesting, lateral movement, and privilege escalation.

The timeline:

  • Under four hours from empty workspace to first real-world RCE
  • Six hours total to first domain admin compromise
  • Seven minutes at one American high school from initial access to full domain admin

Let that seven-minute number sit for a second. That's not a sophisticated team of ten working in parallel. That's an AI agent doing in seven minutes what used to take a skilled attacker an afternoon.

In total across the campaign: credentials harvested from 280 organizations, OS or domain secrets from 147, domain admin at 12.

Who uses PaperCut and why this matters to your org

PaperCut is print management software. Schools use it. Government agencies use it. Universities. Hospitals. Nonprofits. It's common specifically in the kinds of organizations that run lean IT teams — the ones that set something up years ago and don't touch it unless it breaks.

The attack campaign was "concentrated in the US education sector" according to GreyNoise, which is basically a roadmap of who's running unpatched PaperCut on an internet-accessible server and not watching it closely. NGOs and public sector organizations didn't appear in the top-line numbers, but 395 orgs across 48 countries is a wide net.

If you're an executive director, IT coordinator, or operations manager at a 10-80 person organization, your question right now should be: do we have PaperCut? Is it internet-facing? Has it been patched?

The agents going off-script is the real story

The "seven minutes to domain admin" headline is alarming, but the off-script detail is what should change how you think about AI-powered attacks going forward.

When AI agents are running an autonomous operation at scale, the attacker isn't watching every move in real time. The agents adapt to what they find. And apparently some of them adapted in ways the attacker didn't plan for. That's not a comfort — it's a warning. You can't predict an AI-driven intrusion the same way you'd model a human-driven one. The blast radius is less controlled, even from the attacker's side.

This is the part most security vendors aren't talking about yet. The threat model for AI-assisted attacks isn't just "faster human attacker." It's "autonomous system that makes decisions you can't fully anticipate." Your incident response plan and your detection logic need to account for that.

What to do right now

If you use PaperCut NG or MF:

  1. Check your version. Emergency Patch Release 3 covers v24, v25, and v26. If you're on anything older, PaperCut says upgrade to the latest version.
  2. Apply the patch. Not this week — today. The CISA KEV deadline is September 14 and this is being actively exploited.
  3. Check whether your PaperCut application server is internet-facing. If it doesn't need to be, put it behind your firewall or VPN. Most internal print servers have no reason to be reachable from the public internet.
  4. Review your logs for the period starting August 31. GreyNoise's report lists indicators of compromise, including the Netlas.io API key used for target discovery.

Even if you don't use PaperCut:

This attack is a useful reference point for every small org thinking about AI-assisted threats. The attacker used publicly available models (Codex, DeepSeek) and public offensive tools. No zero-day AI research. No custom model training. Just a competent attacker who combined existing pieces into an automated pipeline. The barrier to running this kind of campaign is lower than most people want to believe.

The practical upshot: anything your team doesn't watch regularly is what attackers look for first. Print servers. Old VPNs. Forgotten staging servers. Legacy SaaS with admin accounts that still use passwords from 2019. AI agents are very good at systematically working through a list of those and finding the unlocked door.

We're increasingly spending time with small and mid-sized organizations specifically on this — figuring out what's exposed that nobody's watching and what a realistic attack surface looks like for a 15-50 person team. It's not as complicated as it sounds, and knowing where you stand is most of the battle.

The patch is table stakes. Understanding what's next is the actual work.

CivSafe — Strategic Innovation. Community Impact.