threat-intel primary (GreyNoise) · MDR corroboration (Blackpoint) · secondary press (The Hacker News / VentureBeat) · not a lab eval breakout

AI agents hacked print servers at 395 organizations across 48 countries

Origin Lane: aiPaperCut NG/MF print servers · 395 named organizations · 48 countries

GreyNoise says a likely Russian-speaking actor used hundreds of AI agents — OpenAI Codex as the harness, a DeepSeek model doing the work — to exploit two PaperCut print-management flaws and compromise at least 440 servers at 395 named organizations in 48 countries, reaching domain administrator at 12 of them.

GreyNoise blog figure for Agents Gone Wild PaperCut AI-agent campaign — support card, not Wire lead splash
GreyNoise “Agents Gone Wild” og/figure. AI-rail support card only — splash stays on UNGA Wire lead. No theater map / disclosure geography. GreyNoise

Key facts

Primary
GreyNoise blog “Agents Gone Wild,” published Sep 9, 2026 — campaign against PaperCut NG/MF via CVE-2026-81578 and CVE-2026-82078
Actor start
Aug 31, 2026 from IP 45.142.193.132 (tracked by GreyNoise since early July for other edge-product probing); likely Russian-speaking actor (GreyNoise)
Stack
Hundreds of AI agents; OpenAI Codex harness + DeepSeek model (GreyNoise: not OpenAI models for generation) + public offensive tools (Mimikatz, SharpHound, Certipy, Rubeus, Impacket named)
Scale
≥440 PaperCut MF/NG instances · 395 identified victim orgs · 48 countries · other unattributed victims exist
Speed stamps (GreyNoise)
Empty workspace → first real-victim RCE in <4 hours; once campaign launched, ≥11 orgs compromised in 26 seconds; one U.S. high school: initial access → full domain admin in 7 minutes; domain admin at 12 orgs total (fastest 5 min, longest 144 min)
Credential path
Active Directory / credential harvesting via DCSync / NTDS.DIT dumps where domain admin achieved; GreyNoise industry table: Education 204 of 440 victims
Restraint failure
Adversary hard-coded avoid-list of 28 countries; GreyNoise victimology shows hits in some excluded countries anyway (“Agents Gone Wild”)
Goal / corroboration
Goal unclear (access broker vs theft/ransomware). Blackpoint via THN Sep 10: exposed operator infra; AI-assisted research–exploit–retry loop with Hindsight + AionUi. VentureBeat Sep 16: CISA KEV federal deadline Sep 14 (secondary carry)
Scope
Distinct from boarded OpenAI Hugging Face eval breakout, Gemini Irregular CTF, Anthropic fourth cyber-eval, and Hawley Senate probe cards. Operational-agent twin: real victims, print-queue door into Active Directory. No theater map / disclosure geography.
Live
Later victim revisions, CISA KEV confirmation, ransomware follow-on → HUD. Not a claim that OpenAI models themselves wrote the PaperCut exploits.

Agents Gone Wild

GreyNoise report title for the PaperCut NG/MF AI-agent campaign, Sep 9 2026

Note

GreyNoise’s September 9 report says a likely Russian-speaking actor used hundreds of AI agents to research, build, and run exploits against PaperCut NG and MF print-management software — chaining CVE-2026-81578 and CVE-2026-82078 — and compromised at least 440 servers tied to 395 named organizations in 48 countries.

The agents ran on an OpenAI Codex harness with a DeepSeek model and a kit of public hacking tools. GreyNoise’s speed stamps: under four hours from an empty workspace to the first real remote-code-execution hit; once the campaign launched, at least eleven organizations compromised in twenty-six seconds; one U.S. high school from first access to full domain administrator in seven minutes. Domain admin landed at twelve organizations total. Education took the heaviest share of victims. The actor tried to skip twenty-eight countries; GreyNoise says some of those countries still showed up in the victim list — the title of the report is “Agents Gone Wild.”

Blackpoint Cyber, covering the same campaign, describes an exposed operator workspace where AI kept the research–exploit–retry loop running with persistent agent memory. End goal still unclear: access for someone else, or later theft and ransomware. Attribution: GreyNoise Sep 9 primary; The Hacker News / Blackpoint Sep 10; VentureBeat Sep 16 carry. Distinct from boarded lab-eval breakout cards. Live later victim revisions, CISA KEV confirmation, and any ransomware follow-on → HUD.

Why it matters

This is not another sandbox warning shot. It is agents in the wild, writing and running exploits against real print servers — schools hardest hit — and walking some of them to domain admin in minutes. Same season as the lab-eval breakout cards, with named victims.

Sources

Primary + secondary attribution as listed. Live values go to the HUD / source product.

Daily board