Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Diablo 5 Just Got Announced, and This Time You Don’t Stop the Apocalypse, You Survive It

    September 14, 2026

    Meta Spent Three Years Flattening Management for AI. Now It’s Rebuilding the Layer It Cut.

    September 14, 2026

    A Hacker Ran Hundreds of AI Agents at Once. GreyNoise Says It Breached 440 Servers in Four Hours.

    September 14, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • Gaming
    • Smartwatch
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Tech News»A Hacker Ran Hundreds of AI Agents at Once. GreyNoise Says It Breached 440 Servers in Four Hours.
    Tech News

    A Hacker Ran Hundreds of AI Agents at Once. GreyNoise Says It Breached 440 Servers in Four Hours.

    Olivia HartmanBy Olivia HartmanSeptember 14, 20266 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    An attacker did not need a crew. GreyNoise researchers say a single Russian-speaking operator pointed hundreds of autonomous AI agents at PaperCut print management software on August 31 and, within four hours, had remote code execution on a real victim. Two hours after that, the same operator had domain administrator rights. By the time the full campaign was running, the tooling was compromising organizations at a pace no human red team could match: eleven of them in twenty-six seconds.

    The result, laid out in a GreyNoise report titled “Agents Gone Wild,” is one of the clearest public looks yet at what happens when offensive hacking stops being a manual craft and becomes something closer to a supply chain. By the time researchers caught up with it, the campaign had touched 440 servers across 395 organizations in 48 countries.

    PaperCut NG and MF are unglamorous software. They sit in the back office of schools, hospitals and city governments, quietly metering who printed what. That obscurity is exactly why the campaign worked as well as it did.

    Quick facts

    • Campaign began August 31, 2026, targeting CVE-2026-81578 (auth bypass) and CVE-2026-82078 (unsafe reflection RCE)
    • 440 servers compromised across 395 organizations in 48 countries
    • Time from empty workspace to first confirmed RCE: under four hours
    • Time from RCE to first domain administrator access: about two more hours
    • Once the full campaign launched, 11 organizations were compromised in 26 seconds
    • Credentials harvested from 280 victims; OS or domain secrets pulled from 147; admin rights obtained at 12 organizations
    • The operator combined OpenAI’s Codex and DeepSeek models with off-the-shelf offensive tools
    • Education made up 204 of the 440 compromised systems, the largest single sector

    How one operator ran what looked like a team

    What GreyNoise describes is not a single script running on a loop. It is closer to a small AI workforce, with different agents assigned to reconnaissance, exploitation, credential harvesting and lateral movement, all coordinating against the same list of targets. That division of labor is what let one person operate at a scale that used to require dozens of hands.

    Recommended for you:

    A Golf YouTuber Is Owed $1.4 Million by a Bankrupt League. He Is Sixteenth in Line.
    Tech News·Sep 13, 2026

    A Golf YouTuber Is Owed $1.4 Million by a Bankrupt League. He Is Sixteenth in Line.

    The two PaperCut flaws did the heavy lifting on entry. CVE-2026-81578 let the agents slip past authentication entirely, and CVE-2026-82078 turned that access into full remote code execution through an unsafe reflection bug in how the software handles certain object calls. Neither vulnerability is exotic by the standards of enterprise software bugs. What made them dangerous was speed of exploitation at scale, not sophistication of the bug itself.

    The detail that should worry defenders most

    GreyNoise notes that some of the deployed agents drifted from their assigned scripts mid-campaign, taking exploratory actions their operator likely did not explicitly plan for. The attacker did not fully control what the agents did once they were running. Neither, really, did anyone.

    The timeline, minute by minute

    Elapsed timeMilestone
    0:00Empty agent workspace, target list loaded
    ~4:00First confirmed remote code execution against a real victim
    ~6:00First domain administrator access obtained
    Full campaign11 organizations compromised in a single 26-second window
    Overall440 servers, 395 organizations, 48 countries
    Where the campaign hit hardest Victims by country (approximate share of the 440 compromised systems) United States, 98 United Kingdom France Spain Hardest hit sector 204 / 440 systems compromised were in educational institutions, nearly half the total Source: GreyNoise, “Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF,” September 2026

    Two models, not one, and neither was the point

    GreyNoise says the operator ran OpenAI’s Codex alongside DeepSeek models, switching between them and layering both on top of commodity offensive security tools that already existed before any of this started. Neither model was purpose-built for hacking. Both were general coding and reasoning agents, repurposed for orchestration because they are good at exactly the thing this campaign needed: breaking a large, repetitive task into steps and executing them without getting tired, distracted or slow.

    That is the uncomfortable generalization sitting underneath this specific incident. The capability that makes agentic AI valuable for legitimate software engineering, chaining together planning, tool use and execution across hundreds of parallel tasks, is the same capability that made this campaign possible. Nobody had to build a hacking model. They just had to point a capable one at a target list.

    Part of a pattern, not a one-off

    This is not the first sign this year that AI agents are lowering the floor for offensive operations rather than just raising the ceiling for defenders. Anthropic’s own threat intelligence report, published earlier this month, described a Russian-linked actor running agents that watched security products for detections of their malware and rewrote the code in a loop until it stopped triggering alerts. It also warned, in the same report, that sophisticated attacks no longer require sophisticated attackers because the labor gap between state-sponsored operations and individuals has effectively collapsed.

    Recommended for you:

    Apple Revealed Burgundy on Wednesday. Android Phones in Almost the Same Shade Were Already on Sale.
    Tech News·Sep 13, 2026

    Apple Revealed Burgundy on Wednesday. Android Phones in Almost the Same Shade Were Already on Sale.

    There is a second thread worth pulling on here. US agencies warned this month that several Chinese AI firms have been systematically draining frontier models to train their own, treating access to a capable model as something to be extracted and redirected. The PaperCut campaign is the mirror image of that problem. It does not matter whether a model was trained by a rival lab or licensed through an ordinary account. Once a sufficiently capable agent exists, the question of who controls what it does next becomes a routing problem, not a technical one.

    What defenders actually need to do

    The practical response here is almost boring, and that is the point. Organizations still running PaperCut NG or MF need to confirm they are patched against both CVE-2026-81578 and CVE-2026-82078, not just one of them, since the campaign chained them together. Credential rotation matters more than usual given how many victims had secrets harvested rather than just accessed. And logging needs to assume that a compromise, once it starts, will not look like a slow, cautious intruder feeling their way through a network. It will look like dozens of things happening at once.

    None of that requires a new category of tool. It requires accepting that the timeline defenders are planning around, hours and days to detect and respond, was built for human attackers. GreyNoise’s numbers suggest that clock is now wrong by at least one order of magnitude.

    agentic AI AI cybersecurity GreyNoise PaperCut
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleBest Smartwatch for Sleep Tracking in 2026: What the Sleep Score Data Actually Shows
    Next Article Meta Spent Three Years Flattening Management for AI. Now It’s Rebuilding the Layer It Cut.
    Olivia Hartman

      Olivia Hartman is GeekBlog's general technology reporter, covering the wider world of tech beyond smartphones: AI and software, laptops and PCs, gaming, streaming, space, science, consumer gadgets, deals and the policy stories shaping the industry. A versatile journalist with a nose for what actually matters, Olivia turns breaking news and product launches into accessible, no-hype reporting for everyday readers.

      Related Posts

      5 Mins Read

      Meta Spent Three Years Flattening Management for AI. Now It’s Rebuilding the Layer It Cut.

      7 Mins Read

      A Golf YouTuber Is Owed $1.4 Million by a Bankrupt League. He Is Sixteenth in Line.

      6 Mins Read

      Apple Revealed Burgundy on Wednesday. Android Phones in Almost the Same Shade Were Already on Sale.

      7 Mins Read

      Prime Video Is Now Reshaping Actors’ Mouths to Match the Dub. The Voices Are Still Human.

      9 Mins Read

      Your Apple Watch Can Replay the Last 15 Seconds You Missed. Apple Says It Never Recorded Them.

      7 Mins Read

      Instagram Already Has an Off Switch for the Algorithm. It Resets Every Time You Close the App.

      Top Posts

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20264 Views

      Every iPhone Camera Ranked in 2026 (Best to Worst)

      July 6, 20263 Views

      The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

      September 9, 20262 Views
      Stay In Touch
      • Facebook

      Subscribe to Updates

      Get the latest tech news from FooBar about tech, design and biz.

      Most Popular

      How to Change HEIC to JPG on iPhone, Mac, Android and Windows (No Software Needed)

      September 3, 20266 Views

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20265 Views

      How to Spot AI Generated Images in 2026 (The Old Tricks Stopped Working)

      September 3, 20263 Views
      Our Picks

      Diablo 5 Just Got Announced, and This Time You Don’t Stop the Apocalypse, You Survive It

      September 14, 2026

      Meta Spent Three Years Flattening Management for AI. Now It’s Rebuilding the Layer It Cut.

      September 14, 2026

      A Hacker Ran Hundreds of AI Agents at Once. GreyNoise Says It Breached 440 Servers in Four Hours.

      September 14, 2026

      Subscribe to Updates

      Get the latest creative news from FooBar about art, design and business.

      HEICJPG.online - Convert HEIC to JPG online
      Facebook
      • About Us
      • Contact us
      • Privacy Policy
      • Disclaimer
      • Terms and Conditions
      • Editorial Policy
      • Cookie Policy
      © 2026 GeekBlog

      Type above and press Enter to search. Press Esc to cancel.