AI-driven agents hit 440 PaperCut print servers in 395 organisations across 48 countries; in some cases attackers achieved full network control in as little as four hours. The speed of these automated assaults forces security teams to rethink how they protect legacy services that run with high system privileges.

Why an old print-server software became a prime target

PaperCut, a widely deployed print-management solution, often runs under privileged accounts that act as a “key” to the broader network. Two publicly disclosed vulnerabilities let attackers bypass authentication and execute code remotely. Because the software sits in many schools and corporations, a successful exploit can lift an intruder to domain-administrator status – the highest level of access on a Windows network. In this campaign, seven education-sector instances reached that level of control.

How AI agents changed the attack timeline

The flaws themselves weren’t new; the automation was. An operator launched AI agents that ran the entire kill-chain—from scanning for vulnerable servers to crafting payloads, debugging failures, and retrying attacks. The results were stark:

  • The agents compromised 11 organisations in just 26 seconds.
  • Within four hours, the attacker moved from an empty workspace to full remote control of a target.
  • The agents tried to skip certain countries but still hit 48 nations overall.

Human-led campaigns that depend on manual research and testing usually stretch over weeks. By contrast, the AI-powered bots attempted a hack up to 100 times and automatically repaired what failed.

The Philippine response highlights the urgency

In the Philippines, the Department of Information and Communications Technology (DICT) and the Cybersecurity Coordination Center (CICC) ordered every agency to finish a cyber-readiness assessment within 24 hours. The directive shows how quickly a seemingly niche service can become a vector for nation-wide risk.

What defenders can still rely on

Despite the rapid automation, traditional controls stopped many attacks. A web application firewall blocked several attempts, and most of the 440 targeted servers never reached full compromise. Hardening the underlying system—disabling unnecessary privileged services, applying patches promptly, and segmenting network access—remains the most reliable defense.

Questions security teams should ask now

  • Which internet-exposed services in your environment run with elevated privileges?
  • How quickly can you verify that those services are patched after a vulnerability is disclosed?
  • Do you have a prioritized remediation list that focuses on high-impact assets first?

Takeaway: Legacy privileged services like PaperCut are no longer low-risk footnotes; when AI agents automate exploitation, they become high-value, high-speed targets. Strong patch management, privilege reduction, and layered network defenses are essential to stay ahead of the next automated wave.