Timeline cards reading 4 hours to first break-in, 6 hours to full control, 26 seconds for 11 organizations, above the headline: Eleven organizations fell in 26 seconds.
Wispr Flow

Wispr Flow turns your voice into clean, ready-to-send writing — speak naturally, it strips the filler and fixes the punctuation. I've used it daily since February 2026 to build this newsletter. Read the full review →

On the last day of August, someone pointed a few hundred AI agents at the internet and told them to find print servers.

Not a metaphor. Actual agents, running on their own, hunting for a specific piece of office software. Within four hours of that attacker sitting down to work, the agents were inside their first real victim. Two hours later they had full control of that organization's network. And once the campaign was running, eleven separate organizations were broken into in twenty-six seconds.

The threat intelligence firm GreyNoise watched it happen and published the breakdown on September 9.

The target was print management software — PaperCut NG and MF, the kind of dull, invisible server that schools and offices use to track who printed what. It usually sits on the company network with high privileges, which is what made it worth attacking. PaperCut had warned customers in late August that two flaws were already under attack, and shipped emergency fixes. The first fix was incomplete.

The agentic era needs a different CRM. That’s Attio.

Parallel, Turbopuffer, and Wordsmith run their entire GTM motion on Attio, with agents that chase every buying signal, build pipeline, and move deals forward, 24/7.

A human did the hard part once. The attacker built a private lab, worked out how to break in, and tested it. The operation then built its target list using an internet scanning service, and hundreds of AI agents attacked the machines on that list, afterward choosing their own method at each victim based on what they found inside.

The final count: 440 machines at 395 organizations in 48 countries. Just under half were schools and universities. Credentials were taken from 280 of them. Twelve lost full control of their networks.

The clock is the real story. Under four hours from a blank workspace to breaking into a real victim. Two more hours to full network control. Twenty-six seconds to break into eleven organizations at once. At one American high school, seven minutes from the front door to the whole building. A patch cycle measured in days does not fit inside numbers like that.

The agents also ignored their own orders. The attacker gave them a list of 28 countries to leave alone, including Russia, China, Brazil and Nigeria. The victim list includes China, Kazakhstan, Brazil and Nigeria. GreyNoise called its report Agents Gone Wild. Even the person running the agents could not fully control them.

What still worked is the part worth keeping. At one company, the agents hit a server they thought was vulnerable and a web application firewall simply stopped them. And only 12 of 440 break-ins reached full network control — the organizations with tidier internal setups lost credentials, not the whole building. Ordinary security work still helps, even against this.

If your organization runs PaperCut on its own server: update to the current version rather than the first emergency patch, get the admin console off the open internet, and assume you may already have been visited — the attacks started before the patch existed. GreyNoise publishes a list of specific things to look for.

If you don't run it, which is most of us, three things carry over. The boring, forgotten machine is how people get in. The gap between a flaw going public and being attacked has closed to almost nothing. And agents are not reliably controllable even by the people running them — worth remembering the next time a vendor describes an autonomous agent as simply following instructions.

The comforting version of AI security was that attackers would still need rare skills. That is over. The skill was needed for four hours, once. The rest was volume.

The site version has the full scorecard, an interactive timeline of how fast it moved, and a free copy-paste prompt for auditing what you have exposed.

Most AI Tools Weren't Built for This

B2B customer issues move across teams and systems, not through a single chat window. A new Harvard Business Review Analytic Services briefing paper, sponsored by Front, breaks down where AI tools fall short in B2B service and what to ask before you invest.

Next time something breaks, what's your actual first move?

One tap. The split decides what I dig into next.

Login or Subscribe to participate

— Jerry