The homework assignment that broke into 440 companies
You have 48 hours between when a security flaw goes public and when someone breaks into your system using it. That used to be enough time. Last month, it wasn't.
A threat actor — likely Russian-speaking, according to researchers — used hundreds of AI agents to exploit a vulnerability in PaperCut, a print management system used by schools, hospitals, and businesses worldwide. The attacker didn't write the exploit manually. They fed the vulnerability details to AI agents and let them work in parallel, testing variations, refining approaches, and iterating faster than any human team could. Within days, 440 organizations were compromised. Most hadn't finished reading the security bulletin yet.
This wasn't a nation-state with unlimited resources. This was someone with an API key and a good prompt. The AI agents did the rest — and they did it faster than the patch could roll out.
What just changed (and why nobody saw it coming)
Here's what actually happened. When a new vulnerability gets disclosed, security teams have always had a narrow window to patch before attackers develop working exploits. That window used to be measured in weeks, sometimes days. It depended on how long it took a human attacker to understand the flaw, write the exploit code, test it, and deploy it at scale.
AI agents just removed that dependency. They don't need to understand the vulnerability the way a human does. They don't get tired. They don't need to sleep or coordinate across time zones. You can spin up hundreds of them, point them at the same problem, and let them explore every possible approach simultaneously.
In the PaperCut campaign, that's exactly what happened. The attacker used what researchers are calling "AI-powered exploit development" — not a single AI writing code, but a swarm of agents testing, refining, and validating attacks in parallel. The vulnerability was disclosed. The AI agents went to work. By the time human defenders were scheduling patch windows, the attackers were already inside.
One researcher put it bluntly: "Give an AI agent a mere rumor of an exploit, and it's enough for them to find it." You don't even need the full technical details anymore. A vague description is enough. The AI fills in the rest.
The gap is closing faster than patches can deploy
This isn't theoretical anymore. It's happening right now, and it's accelerating.
Anthropic — the company behind Claude — just published a report confirming that cybercriminals and state-sponsored hackers are both using AI models to automate attacks. One Russian state-sponsored group was caught using Claude to rebuild malware after detection. Another campaign used AI agents to develop exploits and steal data across multiple victims. These aren't isolated incidents. They're the early pattern of something bigger.
The timeline has collapsed. Vulnerabilities that used to give defenders a week to respond now give them less than 48 hours. And AI agents work around the clock. They don't wait for business hours. They don't need approval from a manager. They start the moment the vulnerability drops, and they don't stop until they get in.
The uncomfortable truth nobody wants to say out loud: the AI tools your security team uses to defend faster are the same tools attackers use to break in faster. And right now, the attackers are winning the speed race.
What you can actually do about this
You can't outrun AI agents. But you can shrink the window they have to work.
1. Patch print management systems this week. If you use PaperCut, Papercut MF, or Papercut NG, update immediately. These systems handle authentication for printers, scanners, and document workflows — which means they touch more devices and credentials than you think.
2. Subscribe to your vendors' security feeds. The organizations that got hit in the PaperCut campaign didn't know the vulnerability existed until after they were breached. Sign up for email alerts from every critical system you use — especially anything that manages access, identity, or authentication.
3. Assume 48 hours is the new patch window. If a critical vulnerability drops on Friday afternoon, you no longer have until Monday. Build a plan now for emergency weekend patching. Identify who has authority to approve it and who can execute it outside business hours.
4. Turn off services you're not actively using. Every dormant admin portal, every "we'll migrate off that eventually" legacy system, every test environment still running in production — those are the systems that don't get patched in 48 hours. Shut them down or isolate them.
5. Watch for login attempts from unexpected locations. AI-driven exploitation campaigns move fast, but they still leave traces. If you see authentication attempts on systems that don't normally get external traffic, investigate immediately — don't wait for the alert to escalate.
Have you seen it yet?
Have you encountered a vulnerability disclosure at your organization where the time between announcement and active exploitation felt impossibly short? What system was it, and how much time did you actually have?
Identity Decoded publishes every week at identity-decoded.com
