Palo Alto's Unit 42 just caught a Chinese-speaking threat actor running DeepSeek AI through the Hermes Agent framework.
One Telegram command. Then the agent operated alone.
It scanned 460+ exposed servers, researched CVEs, downloaded exploit code, and launched attacks — all without a human touching the keyboard.
The agent compressed hundreds of hours of manual targeting into minutes.
It selected Langflow first. Found 84 exposed instances. Scanned them. Determined they couldn't be exploited. Pivoted to n8n. Found 647,000 exposed instances. Downloaded a two-CVE exploit chain. Checked for unauthenticated upload forms. They required authentication. The agent abandoned that path and moved on.
This is not a proof of concept. This is an operational attack workflow running in the wild.
The attacker also had Claude Code, OpenAI Codex, Qwen, and MiniMax configured on the same server. DeepSeek was the primary brain. The others were backup options.
Three organizations were actually compromised through Citrix NetScaler memory disclosure. Session tokens extracted. Authentication cookies hijacked.
Your security team's entire assumption about AI-powered attacks is wrong. You built controls around the idea that attacks need human decision-makers at each step. That model just broke.
Audit your exposure management tonight. If you have internet-facing Langflow, n8n, Marimo, or NetScaler instances, patch or pull them offline. The next agent won't make the same mistake this one did — accidentally spinning up a web server that exposed its own API keys and attack logs.
DeepSeek just ran autonomous cyberattacks across 460 targets. Your human-in-the-loop controls are theater.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments