← Founder Notes
Archive

Ai agents have collapsed the exploit window from weeks to hours. an attack wave reported september…

Yethikrishna ROriginal on Threads

ai agents have collapsed the exploit window from weeks to hours. an attack wave reported september 11 hit 395 organizations across 48 countries through unpatched papercut servers, and mass exploitation now follows disclosure within hours.

patch cadence is the new security boundary.

Context

GreyNoise's research post of 9 September 2026 describes a likely Russian-speaking actor who on 31 August 2026 used AI to develop, test and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078), with hundreds of agents on OpenAI's Codex harness with a DeepSeek model. It says the campaign went from an empty workspace to a first RCE on a real victim in just under four hours, with exploits tested against patched and unpatched servers and opportunistic targeting including many US education targets. A Cloud Security Alliance note summarizing it says Huntress detected first in-the-wild exploitation on 26 August 2026 and PaperCut disclosed the issues the next day. The Register (10 September) and Help Net Security (11 September) cover it, and TechRepublic's headline says 440 servers.

How it compares

The campaign and AI agent use are first-party from GreyNoise. The 395 organizations appears in the CSA title and a Register headline, and the primary count was not located in the GreyNoise text read; TechRepublic's 440 servers is a different unit and is unreconciled. 48 countries was not found in any source read. September 11 is later than the first reports of 9 and 10 September. Under four hours is the attacker's time from empty workspace to first RCE, not the time from disclosure to exploit, and CSA's dates put exploitation before disclosure, so mass exploitation within hours of disclosure is not supported by this campaign. It is one case study and not a measure of the exploit window in general.

Watch next

  • GreyNoise's primary victim and country counts and any PaperCut or CISA advisory.

Sources

  1. AI-orchestrated campaign against PaperCut NG/MF (GreyNoise)greynoise.io
  2. PaperCut AI agent swarm exploitation (Cloud Security Alliance research note)labs.cloudsecurityalliance.org
  3. Hundreds of AI agents helped PaperCut attacker hit 395 orgs (The Register, 10 Sep 2026)theregister.com
  4. AI agents PaperCut NG/MF attack campaign (Help Net Security, 11 Sep 2026)helpnetsecurity.com

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 21 September 2026 at 00:17 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/ai-agents-have-collapsed-the-exploit-window-from-DdhQ1FvjRGG" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="Ai agents have collapsed the exploit window from weeks to hours. an attack wave reported september…"></iframe>

More notes