GreyNoise has published an account of a campaign that is worth reading carefully, because the interesting part is not the vulnerability. It is the tempo.

What happened

A single attacker, assessed as Russian-speaking, exploited two flaws in PaperCut NG/MF print management software, tracked as CVE-2026-81578 and CVE-2026-82078. The result was at least 440 compromised systems across 395 organisations in 48 countries.

The attacker first built a private lab with a vulnerable copy of PaperCut and an Active Directory server, then developed and tested the exploits there. The agents ran on OpenAI's Codex harness paired with a DeepSeek model, alongside publicly available offensive security tools.

The speed is the story

From an empty workspace to remote code execution against a real victim took just under four hours. First domain admin followed two hours after that. Once the campaign launched properly, eleven organisations were compromised in 26 seconds.

Credentials were harvested from 280 victims. Operating system or domain secrets came from 147. Administrator privileges were obtained at 12 organisations.

Who was hit

Education dominated with 204 victims, far ahead of retail, professional services and hospitality, with government, healthcare and legal organisations scattered behind. GreyNoise attributes the skew to PaperCut's customer base rather than deliberate targeting — the agents went after whatever was reachable.

Why it matters

Patch windows have always been a race between defenders and attackers, and both sides moved at human speed. That assumption is what broke here. An attacker who can go from a fresh workspace to working exploitation in four hours, then hit eleven organisations in under half a minute, has compressed the window to something no manual patching process can meet.

The tools involved were not exotic. A coding harness, an open-weight model and off-the-shelf offensive utilities. That combination is available to anyone, which is the uncomfortable part.