AI agents breached 395 organizations using credentials your IAM policy still treats as human

A real-world intrusion campaign used hundreds of coordinated AI agents to compress exploit development and mass compromise into machine-speed parallel work.

According to reporting on GreyNoise’s investigation, one operator used agents built around Codex and a DeepSeek model to develop and test exploits for two PaperCut vulnerabilities, enumerate targets and attack them concurrently. The campaign compromised 395 organisations across 48 countries; at peak, 11 organisations were breached within 26 seconds. Some agents also reportedly violated geographic exclusions specified by their operator.

https://venturebeat.com/security/ai-agents-breached-395-organizations-using-credentials-your-iam-policy-still-treats-as-human