Ai agents have collapsed the exploit window from weeks to hours. an attack wave reported september…
ai agents have collapsed the exploit window from weeks to hours. an attack wave reported september 11 hit 395 organizations across 48 countries through unpatched papercut servers, and mass exploitation now follows disclosure within hours.
patch cadence is the new security boundary.
Context
GreyNoise's research post of 9 September 2026 describes a likely Russian-speaking actor who on 31 August 2026 used AI to develop, test and use exploits for PaperCut NG/MF (CVE-2026-81578 and CVE-2026-82078), with hundreds of agents on OpenAI's Codex harness with a DeepSeek model. It says the campaign went from an empty workspace to a first RCE on a real victim in just under four hours, with exploits tested against patched and unpatched servers and opportunistic targeting including many US education targets. A Cloud Security Alliance note summarizing it says Huntress detected first in-the-wild exploitation on 26 August 2026 and PaperCut disclosed the issues the next day. The Register (10 September) and Help Net Security (11 September) cover it, and TechRepublic's headline says 440 servers.
The campaign and AI agent use are first-party from GreyNoise. The 395 organizations appears in the CSA title and a Register headline, and the primary count was not located in the GreyNoise text read; TechRepublic's 440 servers is a different unit and is unreconciled. 48 countries was not found in any source read. September 11 is later than the first reports of 9 and 10 September. Under four hours is the attacker's time from empty workspace to first RCE, not the time from disclosure to exploit, and CSA's dates put exploitation before disclosure, so mass exploitation within hours of disclosure is not supported by this campaign. It is one case study and not a measure of the exploit window in general.
Watch next
- GreyNoise's primary victim and country counts and any PaperCut or CISA advisory.
Sources
- AI-orchestrated campaign against PaperCut NG/MF (GreyNoise)greynoise.io
- PaperCut AI agent swarm exploitation (Cloud Security Alliance research note)labs.cloudsecurityalliance.org
- Hundreds of AI agents helped PaperCut attacker hit 395 orgs (The Register, 10 Sep 2026)theregister.com
- AI agents PaperCut NG/MF attack campaign (Help Net Security, 11 Sep 2026)helpnetsecurity.com
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 21 September 2026 at 00:17 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →