From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.
September 11, 2026
In the waning hours of August, a likely Russian-speaking actor used hundreds of AI agents trained in a lab environment to seek out Internet-connected instances of the print management software Papercut, compromise the software, and opportunistically attempt to compromise Windows Active Directory (AD) environments, according to an analysis published on Sept. 9 by threat intelligence firm GreyNoise. The attack targeted two vulnerabilities in at least 440 instances of PaperCut NG and MF hosted by 395 organizations in 48 countries, the company said.
The incident is notable for the sheer speed with which the AI swarm was able to accomplish its goal.
"It's clear that large language models (LLM) are enabling adversaries to move at greater speed and scale," GreyNoise researchers said in their analysis. "The adversary went from an empty workspace to first achieving RCE [remote code execution] against a real victim in just under four hours, first [Active Directory] domain admin in an additional two hours, and once the full campaign launched, compromised at least 11 organizations in 26 seconds."









