Insights

AI Security

The PaperCut campaign shows how AI can accelerate exploitation

GreyNoise reported 440 compromised PaperCut instances across 395 organizations in an AI-orchestrated campaign. The evidence shows rapid exploitation and privilege escalation, not dwell time collapsing to seconds. Here is what defenders can act on.

September 11, 2026 · 6 min read

The PaperCut campaign shows how AI can accelerate exploitation

A threat actor used hundreds of AI agents to compromise at least 440 PaperCut NG/MF instances associated with 395 identified organizations in 48 countries, according to GreyNoise's September 9 investigation. In one observed case, a United States high school went from initial access to full domain administrator in seven minutes.

I read that as a reason to test the timing of defensive controls, not as proof that every intrusion now happens in seconds. GreyNoise observed domain administrator access at 12 victim organizations. The campaign's outcomes were uneven, and those distinctions matter when translating a threat report into decisions about controls.

What the timing actually tells us

GreyNoise reported three different measurements. The actor moved from an empty workspace to remote code execution against a real victim in just under four hours. First domain administrator access followed an additional two hours later. Once the campaign launched at scale, at least 11 organizations were compromised in 26 seconds.

These figures describe development, exploitation, and privilege escalation. They do not measure dwell time, the period an intruder remains undetected in an environment. Eleven organizations compromised in a short interval also does not mean every one of those intrusions began and ended inside that interval.

The seven-minute high-school example is a concrete initial-access-to-domain-admin measurement. It is enough to challenge a response plan that requires several manual handoffs before anyone can contain a compromised server. It does not establish how quickly the victim detected the intrusion or when the attacker was removed.

For a tabletop, I would keep those clocks separate: first malicious action, first available telemetry, first detection, first containment, and confirmed recovery. A single response-time average can hide a long delay at the one step where intervention would have mattered.

AI helped scale familiar attack paths

The campaign targeted CVE-2026-81578 and CVE-2026-82078 in PaperCut NG/MF. GreyNoise describes the actor building a private lab with vulnerable PaperCut software and an Active Directory server, testing exploitation and credential harvesting, and building target lists through Netlas.

The agents used OpenAI's Codex harness with a DeepSeek model, not OpenAI models. That distinction separates the software coordinating the work from the model generating its decisions. Publicly available offensive tools were part of the operation too.

PaperCut's position in an environment helps explain the risk. GreyNoise notes that the self-hosted Java application defaults to SYSTEM-level privileges on Windows and is usually domain-joined and integrated with Active Directory. Compromising that application can create a path to more consequential access, depending on the surrounding configuration and controls.

Attackers could automate scanning and exploitation long before this campaign. Human operators have also coordinated parallel attacks for years. The significance here is the observed use of AI across development, testing, and execution at scale. The report does not provide a controlled comparison that isolates exactly how much faster AI made each step.

Use the current vendor fix, not a stale emergency build

PaperCut's security bulletin, updated September 10, recommends the security maintenance releases 26.0.5, 25.0.13, and 24.1.10 for the corresponding supported branches. These replace the previously published emergency patches.

PaperCut says the maintenance releases include the fixes from Emergency Patch Releases 1, 2, and 3, plus additional hardening, and have completed its regular release testing. An inventory entry that says only "emergency patch applied" is therefore not a sufficient verification record. Record the installed version and compare it with the current bulletin.

Restrict public access to the application server and follow the vendor's investigation guidance. Updating software closes addressed vulnerabilities; it does not establish that an attacker who already gained access has been removed. Treat exposure reduction, patch verification, and investigation as separate tasks with separate evidence.

I would ask the owner of each installation to document its version, external reachability, service privileges, and network access to directory infrastructure. Those answers make the risk discussion more useful than a generic statement that printing is a low-priority service.

Test what can act before a manual handoff

A practical exercise is to trace a suspected compromise of a domain-joined application server through the controls already deployed. Which event becomes visible first? Which control can block or contain it? What needs a person's approval, and who can give that approval outside business hours?

Modern endpoint products already perform local prevention. This campaign is not evidence that all defenses wait on a central SIEM or that automated prevention must be invented from scratch. The work is to establish whether the relevant protections are enabled, whether they cover this host, and whether the team has tested their behavior.

Containment also has costs. Isolating a print server can interrupt operations. Automated action should follow a reviewed playbook with a defined scope, recovery procedure, and retained evidence. Faster execution is useful only when the action is justified and its consequences are understood.

Measure the actual sequence in your environment rather than promising a universal five-minute defense. A test may reveal missing telemetry, an approval bottleneck, or a network path that makes one compromised server disproportionately dangerous. Each finding has a different owner and remedy.

How CarbeneAI approaches the problem

I use campaign analysis to connect observed behavior to a control decision and the evidence needed to support it. That is the purpose of the Harbinger brief workflow, our open-source threat-intelligence project. It should help a security leader distinguish reported observations from recommendations and untested ideas.

Endpoint Mesh 2.0 explores a local prevention path and optional neighbor signaling alongside central correlation. It is an architectural proposal with explicit implementation limits, not a deployed or validated answer to this campaign. Existing endpoint prevention remains part of the baseline.

For this incident, the immediate priorities are concrete: verify the current PaperCut release, reduce exposure, investigate possible prior compromise, and test the response path. The AI component makes those questions urgent. It does not change the standard of evidence needed to answer them.

Prepared with AI assistance. Campaign figures are attributed to GreyNoise; release guidance is attributed to PaperCut. Recommendations are analysis, not results from testing this campaign in a production environment.