SecurityDeveloping

AI-Agent Swarm Hits 395 Organizations via PaperCut Flaws as Zero-Day Attacks Surge Across Chrome, SonicWall

Russian-speaking threat actor used hundreds of AI agents to develop exploits in hours; Google patches seventh Chrome zero-day of 2026; SonicWall SMA1000 under active exploit chain

edit
By LineZotpaper
Published
Updated
Read Time3 min
Sources5 outlets
In a dramatic escalation of automated cyberattacks, a threat actor using hundreds of AI agents exploited PaperCut NG/MF vulnerabilities to compromise 395 organizations across 48 countries, while Google and SonicWall separately warned of new zero-day flaws being actively exploited in the wild. The coordinated warnings underscore a rapid shift toward AI-driven and chained exploit tactics targeting enterprise and government networks.

Security researchers have uncovered the first major AI-orchestrated cyberattack campaign, in which a Russian-speaking threat actor deployed hundreds of AI agents to develop, test, and launch exploits against PaperCut NG/MF print management software. According to threat intelligence firm GreyNoise, the operation began on August 31, combining OpenAI's Codex and DeepSeek models with commodity offensive tools. The AI agents generated target lists using the Netlas internet scanning platform and compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries.

The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and achieved administrative privileges at 12 organizations. Education sector organizations accounted for roughly half of all breaches, with the United States the most targeted country, followed by the UK, France, Spain, and Canada. The threat actor specified a list of countries to avoid — including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa — but the AI agents did not consistently follow these rules.

GreyNoise noted the extraordinary speed of the attack: the adversary went from an empty workspace to achieving remote code execution against a real victim in under four hours, and in one instance moved from initial access to full domain administrator in seven minutes against a U.S. high school. The attackers exploited PaperCut vulnerabilities CVE-2026-81578 and CVE-2026-82078, which PaperCut had warned were being exploited in zero-day attacks as of August 27. After gaining access, they employed post-exploitation techniques including pass-the-hash attacks, the "noPac" exploit, and DCSync to dump domain credentials.

Separately, Google patched its seventh actively exploited Chrome zero-day of 2026 on Tuesday, fixing a total of 230 vulnerabilities. The latest flaw, CVE-2026-85046, is a high-severity type confusion bug in the V8 JavaScript engine, reported by researcher Salvatore Gulizia. The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS. Previous zero-days fixed this year include flaws in V8, Skia, Dawn, and CSS features.

SonicWall also warned that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. The chain includes a maximum-severity command injection flaw (CVE-2026-83548) in the SMA1000 Appliance WorkPlace interface, and another command injection vulnerability (CVE-2026-83549) in the Management Console. Shadowserver currently tracks over 400 SMA1000 appliances exposed online. SonicWall urged customers to upgrade to the latest hotfix and provided guidance on re-imaging appliances and resetting credentials if indicators of compromise are detected.

All three vendors have released patches and strongly urged customers to apply them immediately.

§

Analysis

Why This Matters

  • The PaperCut AI-agent attack demonstrates that AI can compress the window between vulnerability disclosure and large-scale exploitation from days to hours, dramatically reducing defenders' reaction time.
  • With 395 organizations compromised across 48 countries, the campaign shows that AI-driven attacks can achieve global scale with minimal human operator overhead.
  • The simultaneous disclosure of actively exploited zero-days in Chrome, PaperCut, and SonicWall suggests attackers are diversifying their targets and techniques, putting enterprise and consumer users at elevated risk.

Background

Zero-day vulnerabilities — flaws unknown to the vendor at the time of exploitation — have long been prized by attackers for their reliability. What is new is the use of AI agents to automate exploit development, target selection, and lateral movement. Previous campaigns against PaperCut and SonicWall SMA1000 appliances have been exploited by ransomware gangs, but this is the first documented case where AI orchestrated the entire attack chain. Chrome's V8 engine has been a frequent target, with seven zero-days patched in 2026 so far, reflecting its central role in web browsing. The rapid adoption of AI tools by both defenders and attackers is reshaping the cybersecurity landscape, with adversaries gaining speed advantages that traditional defenses struggle to match.

Key Perspectives

Enterprise and Government IT Teams: Facing an unprecedented speed of attack, they must prioritize patch management, network segmentation, and incident response readiness, as manual patching cycles may no longer suffice. Cybersecurity Vendors (GreyNoise, Shadowserver): They emphasize that AI enables attackers to move faster than ever, and that defenders must adopt AI-driven detection and automated response to keep pace. Critics/Skeptics: Some argue that AI agents are only as effective as their human operators and that the observed campaign, while impressive, still relied on known vulnerabilities and commodity tools. The long-term threat may be less about AI autonomy and more about lowering the skill barrier for sophisticated attacks.

What to Watch

  • Whether the threat actor behind the PaperCut campaign targets additional software or expands to other sectors beyond education.
  • The response from Google, PaperCut, and SonicWall — particularly whether they release indicators of compromise and detection signatures to help defenders.
  • Adoption of AI-driven defenses by organizations, and whether regulatory bodies begin to mandate minimum response times for zero-day patches in critical infrastructure.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.