● This week’s signal » The agents scanned, wrote the exploit, tested it, and scaled it. A person set the goal and then mostly watched.
Signal Over Noise
- AI agent swarm breaches 395 organisations through PaperCut serversSep 9
- TypeSafe AI exits stealth with $40M and a model that returns types, not textSep 15
- Claude Code weekly limits drop 17% in real termsSep 14
- Profound raises $180M at a $1.8B valuationSep 15
- Arcee AI raises $150M at a $1B pre-money valuationSep 16
- Anew Labs raises $290M at a $1.5B valuationSep 16
Story of the Week
One person, a swarm of AI agents, and 395 organisations breached
Security firm GreyNoise published its findings on September 9 under the title “Agents Gone Wild”, and four research teams spent the following week corroborating it. Preparation began on 31 August and the campaign launched the next day, when a single attacker pointed hundreds of AI agents at PaperCut print-management servers. The agents did the work: they found targets through a public scanning service, wrote the exploits themselves, tested them in a lab, then deployed at scale. Three hours and 55 minutes from an empty workspace to the first remote code execution. Then eleven organisations inside 26 seconds of launch. The final count was 440 compromised instances across 395 named organisations in 48 countries. Two details deserve to stay with you. 204 of the 395 victims were schools or universities, and at one US high school the agents went from first access to full domain administrator in seven minutes. Of the 440 instances, 280 gave up credentials and 147 also surrendered operating system and domain secrets, along with thousands of authentication tokens for Google, Microsoft, Amazon, Anthropic and Cursor.
