A suspected Russian-speaking threat actor deployed hundreds of AI agents built on OpenAI’s Codex and a DeepSeek model to exploit two PaperCut NG/MF vulnerabilities, compromising more than 440 instances across 395 organizations in 48 countries. According to security researchers at GreyNoise, the AI agents automated vulnerability research, exploit development, targeting, and post-exploitation activity, sharply reducing the manual effort typically needed for attacks at this scale. The attacker reportedly achieved remote code execution against a real victim in under four hours and gained domain administrator access at some targets within hours of launching the campaign.