AI Agents Exploit PaperCut Vulnerabilities in Global Cyberattack
September 10, 2026
oecd:2026-09-10-3a14View source ↗
What happened
A suspected Russian-speaking attacker used hundreds of AI agents, leveraging OpenAI's Codex and DeepSeek models, to autonomously exploit vulnerabilities in PaperCut print management software. The campaign compromised 440 servers across 395 organizations in 48 countries, rapidly gaining domain administrator access and enabling credential theft and unauthorized control.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
OECD AI Incidents Monitor
AI Agents Exploit PaperCut Vulnerabilities in Global Cyberattack
2026-09-10