BAD SIGNAL

← News

9 Sep 2026

GreyNoise: AI agents hit 395 organizations through PaperCut

Lab note dated 9 Sep 2026. Hundreds of agents, Codex harness plus a DeepSeek model. Victim counts are GreyNoise’s.

9 Sep 2026: GreyNoise published “Agents Gone Wild,” describing a campaign that began 31 Aug 2026 against PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078).

GreyNoise: a likely Russian-speaking actor used hundreds of AI agents — OpenAI’s Codex harness plus a DeepSeek model, not OpenAI models — and public offensive tools to compromise at least 440 PaperCut instances at 395 identified organizations in 48 countries.

GreyNoise timings: empty workspace to first real-victim remote code execution in under four hours; first domain-admin two hours later; once the full wave launched, at least 11 organizations in 26 seconds. A U.S. high school went from initial access to domain admin in seven minutes.

GreyNoise: domain-admin on only 12 organizations; credentials from 280; OS or domain secrets from 147. Education accounted for 204 victims, which GreyNoise ties to PaperCut’s installed base.

The actor listed 28 countries to avoid. GreyNoise says some of those countries were hit anyway — the “agents gone wild” line. Cloudflare’s WAF stopped at least one attempt.

A named sensor shop published a dated agentic-offense case, not a keynote demo. Patch PaperCut. The rest is GreyNoise’s telemetry.

Sources

Comments

Talk under the story. Stay on the sources. Comment guidelines

Loading discussion…

More