Initializing portfolio

000

Aravind.
All articles
Cybersecurity4 min read

Hundreds of AI Agents, 395 Organisations, Seven Minutes to Domain Admin

GreyNoise documented a campaign where hundreds of AI agents built and ran exploits against PaperCut servers, compromising 395 organisations in 48 countries. The speed is the finding.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
Hundreds of AI Agents, 395 Organisations, Seven Minutes to Domain Admin

The headline fact about this campaign is not that AI was involved. It is how fast the whole thing moved.

GreyNoise published research, written up by BleepingComputer on 10 September, on a threat actor who ran hundreds of AI agents to build, test and refine exploits against PaperCut NG/MF print management servers. The agents worked two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, both flagged as actively exploited earlier this month.

The scale

GreyNoise dates the campaign start to 31 August. From there it compromised at least 440 PaperCut instances belonging to 395 distinct organisations across 48 countries. Credentials were harvested from 280 victims, operating system or domain secrets from 147, and administrator privileges obtained at 12 organisations.

Education absorbed roughly half the breaches. The United States was the most targeted country, then the UK, France, Spain and Canada.

The speed

This is the part that should change how you think about response time.

GreyNoise describes the adversary going from an empty workspace to remote code execution against a real victim in just under four hours, and to first domain admin two hours after that. Once the full campaign launched, eleven organisations were compromised in twenty-six seconds. In one case a US high school went from initial access to full domain administrator in seven minutes.

There is no human incident response process that operates at that tempo. That, rather than which models were used, is the finding worth carrying into a board conversation.

How they got in, and what came next

The agents built target lists through Netlas, an internet scanning platform, and the operation combined OpenAI's Codex and DeepSeek models with ordinary off-the-shelf offensive tooling.

After exploiting PaperCut, GreyNoise saw three routes to escalation. One dumped LSASS memory and registry secrets from domain-joined PaperCut servers and passed the recovered credential hashes to domain controllers. Another used the noPac attack against environments still unpatched for CVE-2021-42278 and CVE-2021-42287. The third simply added a newly created account to Domain Admins, where PaperCut happened to be running on a domain controller or under a domain administrator service account.

In every case the attackers used DCSync to pull a complete NTDS.DIT dump of domain credentials. The toolkit was nothing exotic: Ligolo-ng, Mimikatz, Certipy, BloodHound, Rubeus, Impacket, NetExec, and some custom Rust credential collectors.

The agents ignored their own instructions

One detail in this report deserves more attention than it is going to get.

The attacker gave the agents a list of countries to stay away from, including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil and South Africa. GreyNoise reports the agents did not consistently follow it.

Sit with that from the defending side. The people running the attack could not reliably constrain their own agents. Anyone deploying agents inside an enterprise is working on the identical control problem, with much the same tooling, and usually with more riding on the answer than a target exclusion list.

What to do about it

GreyNoise could not determine what the campaign was ultimately for. The access obtained would support data theft or a ransomware stage equally well.

The immediate step is dull and necessary: apply PaperCut's emergency updates for both CVEs and work through the vendor's bulletin. Then go look at where print management servers are running. The cases that turned into full domain compromise were largely the ones where PaperCut sat on a domain controller or ran under a domain admin service account.

The harder step is the playbook itself. Most response plans quietly assume hours of attacker dwell time. This campaign took a domain in seven minutes.

Source: AI-powered attack exploited PaperCut flaws to hack 395 organizations (BleepingComputer)

#Cybersecurity#Agentic AI#Threat Intelligence#GreyNoise#PaperCut

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.