
An AI-agent-driven cyberattack compromised 395 organizations across 48 countries within weeks, exploiting a flaw in the PaperCut printing software. Revealed in early September 2026, the campaign illustrates a concrete shift: AI is now used as much to attack as to defend. The same week, Google, Anthropic, and OpenAI each announced new AI cyberdefense tools. For an SME leader, these two stories belong together.
At a glance
- A campaign that started on August 31, 2026 compromised 440 PaperCut instances across 395 organizations, exploiting two zero-day flaws (source: Bleeping Computer, Help Net Security).
- The attacker combined OpenAI Codex and DeepSeek models with off-the-shelf offensive tools to automate the intrusion, running up to 200 parallel attempts.
- The education sector was hit hardest, with 204 victims among the 395 identified organizations.
- The same week, Google (Gemini 3.8 Flash Cyber), Anthropic (Claude Mythos 5.1 and Enterprise Frontier Safeguards), and OpenAI (a "critical" classification for its Astra model) each strengthened their AI cyberdefense offering.
- For an SME, the lesson is not technical but organizational: patch fast, segment access, and don't rely solely on AI vendors' safeguards.
The PaperCut affair, anatomy of an automated attack
PaperCut NG/MF is print management software used by thousands of organizations, particularly in education and government. According to Bleeping Computer and Help Net Security, an attacker built an exploit in August for two zero-day vulnerabilities, tracked as CVE-2026-81578 and CVE-2026-82078, allowing unauthenticated arbitrary code execution on a vulnerable server.
What sets this campaign apart from classic attacks is what came next. Once the exploit was ready, the attacker did not carry out the intrusion directly: it was handed to AI agents, tasked with finding targets, launching attempts, and exploiting the access gained, with minimal human oversight.
August 31, 2026
Campaign launch
Sept 1-10, 2026
Large-scale spread
Sept 10-11, 2026
Public disclosure
Researchers estimate the attacker harvested credentials at 280 organizations, obtained operating system or domain secrets at 147 of them, and gained full administrator privileges at 12. No large-scale ransom has been reported so far: the campaign appears to have mainly served to establish durable access for later exploitation.
Why this is new
It is not the PaperCut vulnerability itself that changes the picture: software flaws will always exist. What changes is the speed and scale made possible when AI agents run the intrusion autonomously, with dozens of simultaneous attempts and no fatigue.
The labs' response, the same week
As a sign that the industry takes this seriously at the top level, Google, Anthropic, and OpenAI each published cybersecurity-related announcements in early and mid-September 2026.
Google unveiled Gemini 3.8 Flash Cyber on September 2, 2026, a variant of its Gemini 3.8 Flash model reserved for "trusted defenders" (government bodies, critical infrastructure operators, software vendors) through its new Fairwind Program, which already counts more than 650 partners worldwide (source: blog.google).
Anthropic launched Claude Fable 5.1, available to all, and Claude Mythos 5.1, restricted to vetted professionals through its trusted access programs, with permissions dedicated to cybersecurity defense, the same day. The company also announced Enterprise Frontier Safeguards (EFS), a system that keeps customer data within the customer's own cloud while still detecting adversarial misuse, rolling out gradually this fall across AWS, Google Cloud, and Microsoft Azure (source: anthropic.com/news).
OpenAI, for its part, stated that its Astra model now meets the "critical" offensive cybersecurity capability threshold defined by its own Preparedness Framework, and presented a private safety processing system comparable to Anthropic's.
Before this wave of announcements
Since September 2026
What this concretely means for an SME
An SME will almost never get direct access to Gemini 3.8 Flash Cyber or Claude Mythos 5.1, both reserved for verified organizations. But three practical takeaways apply directly.
Patch fast, not eventually
Segment critical access
Ask your AI and security vendors
A table to make sense of it
| Vendor | Tool / measure | Who has access | Announced on |
|---|---|---|---|
| Gemini 3.8 Flash Cyber (Fairwind Program) | Verified defenders (states, critical infrastructure) | September 2, 2026 | |
| Anthropic | Claude Mythos 5.1 + Enterprise Frontier Safeguards | Vetted professionals / Enterprise customers | September 2, 2026 |
| OpenAI | Astra classified "critical" + private safety processing | Internal, disclosed publicly | September 2026 |
Limits worth knowing
This response from the labs is still recent and partial. Most of the AI cyberdefense tools announced are not accessible to an SME without "verified defender" status. They do not replace basic security hygiene: patch management, tested backups, multi-factor authentication. And the PaperCut campaign is a reminder that widely used software, even with no direct link to AI, remains a prime target once an attacker can automate exploitation at scale.
FAQ
What was the 2026 PaperCut attack campaign?
It was a cyberattack that started on August 31, 2026, exploiting two zero-day flaws in the PaperCut NG/MF printing software to compromise 440 instances across 395 organizations in 48 countries. Its distinctive feature was handing most of the intrusion work to automated AI agents.
Is an SME using PaperCut affected?
Any organization running an unpatched version of PaperCut NG/MF is potentially exposed to the CVE-2026-81578 and CVE-2026-82078 vulnerabilities. The priority is applying the vendor's published patches without delay.
What is Google's Fairwind Program?
It is a program launched by Google on September 2, 2026, giving access to Gemini 3.8 Flash Cyber, a cybersecurity variant of its Gemini model, to verified "trusted defenders": government bodies, critical infrastructure operators, and software vendors.
Can an SME access the new AI cyberdefense tools from the major labs?
Rarely directly: these tools (Gemini 3.8 Flash Cyber, Claude Mythos 5.1) are reserved for verified organizations. An SME would benefit indirectly, through its cybersecurity provider or software vendor, if that partner integrates them into its offering.
AI-driven cybersecurity is evolving fast, on both sides. To go further, check out our other resources on cybersecurity and AI or see how SMEs like yours structured their defense in our customer stories.


