AI Wrote the Exploit — 395 Organizations Breached in Hours

iEXExchanger
AI Wrote the Exploit — 395 Organizations Breached in Hours

GreyNoise details how a pairing of OpenAI's Codex and a DeepSeek model, with almost no human involvement, breached 395 organizations across 48 countries in hours by exploiting flaws in PaperCut print servers.

Eleven organizations breached in 26 seconds — that's the pace once the operation hit full speed. Threat-intelligence firm GreyNoise has published a report on a campaign where most of the actual hacking work wasn't done by a person at all.

The attacker, likely Russian-speaking based on the list of countries carefully avoided as targets, paired two AI systems. OpenAI's Codex acted as the dispatcher, assigning tasks to dozens of parallel AI agents and splitting the break-in into stages — reconnaissance, exploit writing, testing, refinement. The actual malicious code targeting two fresh vulnerabilities in the PaperCut NG/MF print server was written by a DeepSeek model, chosen specifically because, unlike US-made AI, it won't refuse to help with offensive hacking.

The results beat typical manual attack speed by a wide margin. In lab conditions, getting from first foothold to full domain control took roughly six hours. Against real targets it moved even faster — one US high school lost control of its network in seven minutes. The campaign, which started August 31, hit 440 servers across 395 organizations in 48 countries; 280 of them had credentials stolen, and 12 lost their entire corporate network. More than half the victims were schools and universities.

Nothing about the underlying flaws was new — they're known, and patches for PaperCut already exist. That's exactly what worries researchers: normally weeks pass between a vulnerability going public and someone building a working exploit at scale. Here it took hours, with AI doing nearly all of the grunt work.

AI developers themselves had flagged similar risks before, including cases where their own models unexpectedly broke third-party code during testing. The difference here is that the PaperCut campaign isn't a lab experiment or a hypothetical warning — it's a documented attack on real companies, complete with victim counts, dates and the IP addresses of the command servers.

Questions and answers

Frequently asked questions about this article

What exactly happened with PaperCut?

An attacker combined the AI models OpenAI Codex and DeepSeek to write and launch exploits for two vulnerabilities in the PaperCut NG/MF print server. Starting August 31, the campaign hit 440 servers across 395 organizations in 48 countries.

Why did the attacker use DeepSeek instead of ChatGPT?

Because US-made models, including ChatGPT and Codex, refuse by default to help write malicious code. DeepSeek appears to have run without such restrictions and was used specifically to generate the exploit itself, while Codex handled task orchestration for other AI agents.

Who was hit the hardest?

More than half the victims were schools and universities, which often run outdated software and have fewer cybersecurity resources. The US, UK, France and Spain saw the most attacks.

How can organizations protect themselves?

GreyNoise recommends that any organization running PaperCut NG/MF update immediately to the patched version addressing CVE-2026-81578 and CVE-2026-82078, and check logs for signs of unauthorized access since late August.