An AI Swarm Compromised 11 Organisations in 26 Seconds
A likely Russian-speaking attacker used hundreds of coordinated AI agents to hunt down, compromise, and pivot through vulnerable installations of PaperCut — print management software used widely in corporate and education environments — according to analysis published by threat intelligence firm GreyNoise, covered by Dark Reading.
The AI swarm went from a blank workspace to achieving RCE (remote code execution — when an attacker runs their own commands on a machine they don't own) against a real victim in under four hours. Once the full campaign launched, the swarm compromised at least 11 organisations across 48 countries in 26 seconds. The attacker also used lateral movement (spreading through a network after gaining initial access) to target Windows Active Directory environments.
Google separately warned on September 8 that the most advanced attackers are now embedding AI agents across every stage of their attack chains.
What you should do: If your organisation uses PaperCut, check that it is patched and not exposed directly to the internet.
Sources

