Palo Alto Networks Unit 42 published research this morning documenting a Chinese speaking operator who wired DeepSeek into the Hermes Agent framework and let it hunt targets on its own over Telegram. The agent enumerated 25,209 hosts and triaged them well, but both of its unsupervised exploit attempts failed, and it leaked the operator's own API keys and target lists to the internet.

Read the full story: Unit 42 caught DeepSeek running its own attack campaign →

Transcript

Palo Alto's Unit 42 just published the first properly logged AI cyberattack. A Chinese operator wired DeepSeek into an agent framework, sent it one message on Telegram, and walked away. The agent did real work. It searched FOFA and found twenty five thousand exposed hosts. It pulled exploit code off GitHub. It ranked targets by severity and by how popular the proof of concept was. Then it probed forty of them and broke into exactly none. Both attempts died on basic authentication. Every real breach in that campaign came from the human doing it by hand afterwards. And the agent's one big impact? It started a file server in the wrong directory and published its own operator's API keys and target lists to the internet. Great scanner. Terrible hacker.