The Cyber Threat Perspective
The Cyber Threat Perspective
The Cyber Threat Perspective·Sep 25, 2026·24m·Episode #197

The Basics Still Win: What GreyNoise's PaperCut Report Shows | Ep 197

Show notes

One threat actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, using AI to run the same playbook at scale. The fastest path to domain admin took five minutes. But out of hundreds of organizations hit, the attacker only got domain admin at 12 of them.

Spencer and Tyler use GreyNoise's recent PaperCut report to make the case that the basics matter more now than they ever have. The attack itself was not novel. It used a known vulnerability, a lab environment built to test exploits, an internet scanning service, and familiar offensive tools. AI (Codex and DeepSeek) is what took it from one target to hundreds.

In this episode:

  • How the attacker built a PaperCut and Active Directory lab to test exploits before going wide
  • Why five minutes to domain admin is fast but not unheard of, and how certificate abuse makes it possible
  • The Conti playbook comparison, and how LLMs are turning attack playbooks into automated campaigns
  • The toolkit: Certify, Rubeus, SpoolSample, Impacket, NetExec, BloodHound, Mimikatz, and AMSI bypasses
  • Why letting hosts reach GitHub directly is a red flag, and how DNS and category filtering slow attackers down
  • The one case where Cloudflare's WAF stopped the attack
  • Why the 12 domain admin compromises are a hopeful sign that hardening works
  • Where to start with AD hardening: tier zero permissions, dangerous rights on broad groups, service accounts, and certificate templates
  • Moving past EDR alone with application control, NDR, and identity-based detections
  • Comparing what a security tool costs to what a compromise costs

Spencer and Tyler are penetration testers at SecurIT360.

If you get something out of the show, subscribe and leave a rating or review. It helps more than you would think.

Work with Us: https://securit360.com
Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov

Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com