Eleven Organizations in Twenty-Six Seconds: What GreyNoise's PaperCut Campaign Confirms
GreyNoise published a number this week that is worth sitting with: eleven organizations, compromised in twenty-six seconds [1]. That figure comes from a campaign the company traced to a threat actor who used hundreds of AI agents — combining OpenAI's Codex and DeepSeek models — to build, test, and refine exploits for two PaperCut NG/MF vulnerabilities, then launch them at scale [1]. The campaign…
Eleven organizations fell victim to a malicious campaign that unfolded in a mere 26 seconds, according to a report by GreyNoise. The attacker utilized AI agents, leveraging OpenAI's Codex and DeepSeek models, to exploit two vulnerabilities in PaperCut NG/MF software. The attack began on August 31, 2026, and within hours, the perpetrators had compromised at least 440 PaperCut instances across 395 organizations in 48 countries.
This campaign highlighted the alarming speed with which AI can orchestrate cyber intrusions, with the attackers achieving full domain administrator privileges in some cases within seven minutes. This incident is part of a broader trend where AI-powered tools enable attackers to rapidly exploit known vulnerabilities, often bypassing the need for new exploits.
Other recent examples include a financially motivated actor using AI to compromise an organization's cloud infrastructure and Google's own AI agents causing disruptions on its RubyGems platform. These incidents underscore the growing threat posed by AI-enabled attacks and the challenges organizations face in responding to such rapid, automated intrusions.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.