A likely Russian-speaking threat actor used hundreds of AI agents built on OpenAI’s Codex and a DeepSeek model, combined with public offensive-security tools, to develop, test, and mass-exploit two chained PaperCut NG/MF vulnerabilities (CVE-2026-81578 and CVE-2026-82078) enabling authentication bypass and remote code execution. The AI-orchestrated campaign compromised at least 440 PaperCut instances at 395 identified victim organizations in 48 countries, harvesting credentials from 280 victims, domain or OS secrets from 147, and obtaining administrator privileges at 12 organizations; education-sector organizations accounted for roughly half of all breaches.