Security researchers have uncovered the first major AI-orchestrated cyberattack campaign, in which a Russian-speaking threat actor deployed hundreds of AI agents to develop, test, and launch exploits against PaperCut NG/MF print management software. According to threat intelligence firm GreyNoise, the operation began on August 31, combining OpenAI's Codex and DeepSeek models with commodity offensive tools. The AI agents generated target lists using the Netlas internet scanning platform and compromised at least 440 PaperCut instances linked to 395 distinct organizations across 48 countries.
The attacker harvested credentials from 280 victims, obtained operating system or domain secrets from 147, and achieved administrative privileges at 12 organizations. Education sector organizations accounted for roughly half of all breaches, with the United States the most targeted country, followed by the UK, France, Spain, and Canada. The threat actor specified a list of countries to avoid — including Russia, China, Iran, Ukraine, Belarus, Moldova, Brazil, and South Africa — but the AI agents did not consistently follow these rules.
GreyNoise noted the extraordinary speed of the attack: the adversary went from an empty workspace to achieving remote code execution against a real victim in under four hours, and in one instance moved from initial access to full domain administrator in seven minutes against a U.S. high school. The attackers exploited PaperCut vulnerabilities CVE-2026-81578 and CVE-2026-82078, which PaperCut had warned were being exploited in zero-day attacks as of August 27. After gaining access, they employed post-exploitation techniques including pass-the-hash attacks, the "noPac" exploit, and DCSync to dump domain credentials.
Separately, Google patched its seventh actively exploited Chrome zero-day of 2026 on Tuesday, fixing a total of 230 vulnerabilities. The latest flaw, CVE-2026-85046, is a high-severity type confusion bug in the V8 JavaScript engine, reported by researcher Salvatore Gulizia. The update brings Chrome to version 152.0.7977.82/.83 on Windows and macOS. Previous zero-days fixed this year include flaws in V8, Skia, Dawn, and CSS features.
SonicWall also warned that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. The chain includes a maximum-severity command injection flaw (CVE-2026-83548) in the SMA1000 Appliance WorkPlace interface, and another command injection vulnerability (CVE-2026-83549) in the Management Console. Shadowserver currently tracks over 400 SMA1000 appliances exposed online. SonicWall urged customers to upgrade to the latest hotfix and provided guidance on re-imaging appliances and resetting credentials if indicators of compromise are detected.
All three vendors have released patches and strongly urged customers to apply them immediately.