Back
OpenAI / DeepSeekModels2026-09-13not yet featured

26 Seconds to Breach 11 Organizations

A likely Russian-speaking attacker ran hundreds of AI agents built on OpenAI's Codex harness and a DeepSeek model to exploit two PaperCut NG/MF vulnerabilities, compromising at least 440 instances at 395 organizations across 48 countries — going from an empty workspace to a live exploit in under 4 hours, then compromising 11 organizations in 26 seconds once the campaign was running.

26 Seconds to Breach 11 Organizations — 1200×675 card for X, Facebook and LinkedIn

Receipts

Flagged:All figures (440 instances / 395 orgs / 48 countries, the 26-second compromise of 11 orgs, the under-4-hour empty-workspace-to-live-exploit timeline, 204 education-sector victims, the 28-country avoid-list) are GreyNoise's own primary research, corroborated verbatim across TheHackerNews, BleepingComputer, The Register and Help Net Security — no discrepancies found across sources. Neither OpenAI nor DeepSeek issued their own disclosure of this campaign; GreyNoise, an independent security research firm, is the sole discloser, which is why the card's top-right tag reads a date rather than 'Primary' (unlike the operator's own Anthropic and OpenAI Navier-Stokes cards, where the implicated company self-disclosed). The attacker's avoid-list (28 countries, led by Russia, China, Hong Kong, Thailand, Iran) is GreyNoise's own stated basis for the 'likely Russian-speaking' attribution, not this card's inference.

THE INTELLIGENCE CLUB

This is one card. Insiders get the whole archive.

Every viral fact card this site has built, in one place, free for Insiders — join now, before the gate goes up.

Join now and you start with 100 Receipts on The Receipts Ledger — your first step toward a free year of Insider or Pro. How it works →

Read this morning's edition →