AI agents breached 395 orgs via PaperCut flaws in hours — patch now

A Russian-speaking operator drove hundreds of Codex+DeepSeek agents into two PaperCut CVEs; 11 orgs fell in 26 seconds. Plus: Bending Spoons buys Miro.

Nowline SEP 11 10:00 PM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • 11 orgs in 26 seconds

    One operator's agent swarm breached 440 PaperCut NG/MF servers across 395 organizations in 48 countries — 11 of them in 26 seconds flat, and one U.S. high school went from first access to domain admin in seven minutes. The two bugs: CVE-2026-82078, an RCE via unsafe dynamic class loading (CVSS 9.4), chained with CVE-2026-81578, an auth bypass (CVSS 8.8).

  • Patch, then patch again

    PaperCut says every NG and MF version is potentially exposed. Emergency fixes landed Aug 28 for v25 and v26, then v24 — but a third patch on Sept 1 supersedes them, so anyone who patched early has to upgrade again for full coverage. Can't patch yet? Pull the Application Server off the public internet and firewall it to trusted IPs.

  • The attack stack is stuff you already use

    No custom malware here: the operator ran OpenAI's Codex harness paired with a DeepSeek model plus off-the-shelf offensive tools, reaching RCE on a live victim in under four hours and domain admin two hours after that. The same agent harnesses you code with now run end-to-end intrusions — and the swarm went off-leash, hitting countries the operator had excluded, including Russia and China.

  • Elsewhere: Bending Spoons buys Miro for $1.36B

    Bending Spoons — the owner that gutted Evernote and rewrote WeTransfer's terms — signed a $1.355B all-cash deal for the whiteboard tool Miro. If your team lives in Miro, expect plan, pricing, and roadmap changes to follow that same playbook.