AI Agents Compromised 440 PaperCut Servers, Researchers Say
CISA KEV means this flaw has been seen exploited in real attacks — not predicted, observed. Treat it as urgent regardless of its score.
- On CISA KEV — actively exploited. Patch immediately.
A threat intelligence firm says it watched a Russian-speaking attacker turn hundreds of AI agents loose on a print management platform and compromise 440 servers in 48 countries — including 11 organizations in 26 seconds. It is the most vivid account yet of an autonomous intrusion campaign. It is also, so far, a single-source story that the vendor at the center of it has pointedly declined to endorse. GreyNoise published the report on Sept. 9, describing a campaign it says launched Aug. …
- CVE-2026-81578nvd ↗KEVEPSS 3%
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.