AI Radar for Companies — Saturday, September 12, 2026
noticias radar ia agentes de ia ciberseguridad automatizacion

AI Radar for Companies — Saturday, September 12, 2026

· CompaniesAutomation

An attacker used hundreds of AI agents with Codex and DeepSeek to compromise 440 PaperCut servers across 395 organizations in 48 countries: Spain is fourth in victims and eleven organizations fell in twenty-six seconds. A study by the Centre for the Governance of AI documents 84 cases of administrations overwhelmed by AI-written claims. China's Enflame raises 911 million in Shanghai and nearly triples in its debut, reaching a 25.5 billion valuation. Microsoft plans to triple data centers to 38 gigawatts with 175 billion in investment in 2026. And Cloudera and Mistral partner to bring models to the data, not the other way around.

Yesterday's radar was about who owns the channel through which you talk to your customers; today's is about how fast the person trying to enter your network is moving now. A single attacker has used hundreds of AI agents to breach 440 print servers across 395 organizations in 48 countries —Spain is the fourth country with the most victims— and took twenty-six seconds to compromise eleven at once. In parallel, a study documents that administrations are already getting clogged with AI-written claims, money continues to flow into silicon —China's Enflame nearly tripled in its stock market debut— and Microsoft is showing the bill for all this: tripling data center capacity to 38 gigawatts.

Hundreds of AI agents assaulted 395 companies via the print server, and Spain was the fourth country

On August 31, an attacker built exploits for two PaperCut NG/MF flaws —CVE-2026-81578, an authentication bypass, and CVE-2026-82078, remote execution— and delegated the dirty work to hundreds of agents powered by OpenAI's Codex and a DeepSeek model. Result: at least 440 compromised instances in 395 organizations across 48 countries, credentials stolen in 280, domain secrets in 147, and domain admin in 12. From an empty workspace to the first remote execution against a real victim took less than four hours; in one American institute, from first access to domain admin, seven minutes; and with the campaign already launched, eleven organizations in twenty-six seconds. Education took 204 of the victims and Spain is the fourth country on the list, with 31, behind the United States (98), United Kingdom (59), and France (31). For your company: what has changed is not the exploit, it's the cost of applying it to everyone at once —you no longer need to be an interesting target, you just need to have the port open. Today: list which server software you expose to the internet (printing, files, VPN, admin panels), check that PaperCut is on the version with the patches, and rotate the service credentials for those machines, because credential theft was the real goal in 280 of the 395 cases. And don't give up on the basics: in at least one attempt, an ordinary application firewall stopped the attacker. Source

AI-written claims are already overwhelming administrations: your inbox is next

A study by the Centre for the Governance of AI and the Hertie School has swept public services in twelve countries and documented 84 cases in eleven jurisdictions where the volume of requests skyrocketed due to the use of AI agents. The figures: complaints to the British housing ombudsman went from 2,600 in 2022 to more than 7,000 last year, and those to the US financial regulator multiplied fivefold in the same period; petitions to the Brazilian judiciary and the German parliament are also soaring. Researcher Chris Schmitz highlights the nuance that makes it uncomfortable: "the vast majority of cases we found are people with a right to claim something, claiming that thing." For your company: the same button that makes it easy for a citizen to write a three-page complaint makes it easy for your customer, and your claims, warranty, or return process is sized for the previous volume. Measure this week how many claims come in and how long it takes to close them; if the curve is already rising, the answer is not to hire someone who reads faster, it's to automate the classification and response of the repetitive and reserve people for what involves financial decisions. Watch out for the other side of the mirror: if your three-page document is generated by an AI, the person receiving it will also screen it with another one. Source

Enflame nearly triples in its debut: money still enters through the chip, not the application

Enflame, the Tencent-backed Chinese AI chipmaker, placed about 43 million shares at 142.18 yuan yesterday on Shanghai's STAR Market and raised 6.12 billion yuan (about $911 million). It opened 188% above the IPO price and closed around 179% up, with a market value of about 170.9 billion yuan ($25.5 billion); retail demand had exceeded supply by 4,000 times. It is the last of the "four little dragons" of Chinese GPUs to go public. The detail worth remembering is not the bounce but the concentration: Tencent holds 20% and also accounted for 84% of its revenue in 2025. For your company: the sector's capital continues to reward the infrastructure layer, not the application layer, and that sets the tone for your renewals —the price of compute has more than enough demand to not drop on its own. And Enflame's 84% is the cheap lesson: if a single customer or a single provider sustains 84% of your figures, your risk is not in the technology, it's in the concentration. Review today what percentage of your billing depends on one customer and what percentage of your automated processes depends on a single model provider. Source

Microsoft triples to 38 gigawatts: the bill that will end up in your renewal

Microsoft plans to reach more than 38 gigawatts of data center capacity by 2032, up from about 12 today, according to Bloomberg. Today only about 2 of those 12 gigawatts are dedicated to AI chips; the forecast is that it will be around one-third of the 38. The company is aiming for about $175 billion in investment in calendar year 2026 and $50 billion just in its first fiscal quarter of 2027, after having previously turned away customers due to lack of capacity. The counterpoint is Oracle, which holds a portfolio of contracted revenue of $664 billion built on its customers' balance sheets. For your company: when the provider turns away business due to lack of capacity, it means they hold the price lever, and the multi-year commitments they offer you today with a discount are the way to transfer that investment to you. Before signing for three years in exchange for 20%, measure your real consumption from the last six months and demand portability in writing: what you take with you and in what format if eighteen months from now the same job costs half as much somewhere else. Source

Cloudera and Mistral: AI that goes to your data instead of your data to the cloud

Cloudera and France's Mistral announced a strategic alliance on September 10 —nine figures, according to industry press— to integrate Mistral's full range of models (reasoning, chat, code, document understanding, and voice) into Cloudera's hybrid platform, which manages about 30 exabytes of customer data. The approach is the reverse of the usual: instead of uploading your data to the model, the model is deployed where the data already is —cloud, on-premises, edge, sovereign, and even air-gapped environments— without sensitive information leaving your control. For your company: if you have shelved a use case because the data could not leave your servers —medical records, case files, payroll, contracts— the argument of "it's not possible" is expiring, and with it the excuse to remain on the manual step. Before getting excited, ask the question that separates marketing from fact: where exactly is the inference executed, who can read the logs of those queries, and what does the contract say about training with your data? If the three answers are not in writing, it is not sovereign. Source

What to watch tomorrow?

Whether identical campaigns to PaperCut's appear against other common server software —the "one exploit, hundreds of agents" pattern is replicable this very week— and if any European regulator speaks out about the overflow of AI-generated procedures, because that is where the first rules on identifying whether the one writing to you is a person or an agent will come from.