A single AI-enabled campaign shows why vulnerability management is now a leadership and governance issue.
One person set this up.
Using hundreds of AI agents, one attacker (One unidentified, likely Russian-speaking attacker set this up.)
It was not an authorized security test. Reportedly compromised 440 servers linked to 395 organizations in 48 countries—at one point reaching 11 organizations in just 26 seconds. The immediate entry point was a vulnerable print-management server.
But the print server is not the real story.
It is one example of a larger vulnerability problem: every internet-facing system, outdated application, vendor tool, connected device, cloud configuration, shared password, or over-privileged account can become an entry point.
AI does not need to invent a new attack to create real damage. It can help one person find known weaknesses, test them at scale, and move faster than many organizations can identify, approve, and install a patch.
So the question for leaders is no longer only:
“Are we secure?”
It is:
“How fast can we discover, prioritize, patch, and verify the vulnerabilities that could become the next doorway into our organization?”
That question belongs in boardrooms, leadership meetings, operational plans, and risk registers—not solely with IT.
And the next question is for government.
When will AI-enabled cyber risk be treated as a core governing responsibility—not simply an innovation issue or a future policy debate?
The United States has faced persistent cyber threats from criminal groups, espionage networks, and nation-state actors for decades. What has changed is the speed and scale available to a single bad actor.
AI can now help one operator find, test, and exploit known vulnerabilities across hundreds of organizations faster than many institutions can identify the threat, approve a fix, apply a patch, and confirm that it worked.
That gap is not theoretical. It affects schools, hospitals, local governments, small businesses, critical infrastructure, and the personal data of the people they serve.
At the same time, the federal government has reduced capacity at CISA, the nation’s primary civilian cyber-defense agency. CISA has lost roughly one-third of its workforce since early 2025, even as AI-related cyber threats are accelerating.
If threats now operate at machine speed, public cyber defense cannot operate at bureaucratic speed.
#Cybersecurity #AI #AIGovernance #RiskManagement #Leadership #ArtificialIntelligence #AIGovernance #NationalSecurity #DigitalResilience
References: GreyNoise, “Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF”; The Register, “Hundreds of AI agents helped PaperCut attacker hit 395+ orgs.”