AI agent swarm compromised 440 PaperCut servers in 26 seconds each
A single threat actor used OpenAI Codex and DeepSeek to build an exploit chain for two PaperCut NG/MF flaws in four hours, compromising over 440 servers across 395 organizations in 48 countries. Eleven organizations fell in 26 seconds each, and a US high school reached full domain admin in seven minutes.
- 440+ PaperCut servers compromised across 395 organizations in 48 countries
- Exploit chain for CVE-2026-81578 and CVE-2026-82078 built in 4 hours with AI
- 11 organizations breached in 26 seconds each; school hit domain admin in 7 minutes
- Attack tied to Russian VPS 45.142.193.132; CISA and NCA issued joint advisory
Read next
Security