A Chinese-speaking threat actor has been using the DeepSeek AI model combined with an open-source framework called Hermes Agent to carry out autonomous cyberattacks on exposed servers with minimal human intervention, according to a new report from Palo Alto Networks’ Unit 42 research team.
The campaign, detailed in a report published on August 1, 2026, represents one of the first documented cases of an AI model being weaponized for end-to-end autonomous offensive operations. The attacker wired DeepSeek into Hermes Agent as a primary reasoning engine, orchestrating the entire attack chain through Telegram for target enumeration, exploit sourcing, and non-interactive execution.
Unit 42 confirmed successful data exfiltration from three organizations through the Citrix NetScaler memory-overread vulnerability CVE-2026-3055, which carries a CVSS score of 9.8. The attacker used the vulnerability to extract memory from NetScaler ADC and Gateway appliances configured as SAML identity providers, then searched stolen memory dumps for authentication cookies that could enable session hijacking.
In addition to the Citrix compromises, the actor achieved command execution on 11 Marimo notebook instances through CVE-2026-39987. The campaign targeted a total of 460-plus internet-facing systems across multiple vulnerability classes, including Apache Tomcat (CVE-2026-34486), Windows IKE VPN (CVE-2026-33824), and Langflow (CVE-2026-33017).
What makes this campaign particularly notable is the level of autonomy achieved. The AI agent was able to independently scan for vulnerable targets, assess exploit paths, and launch attacks without requiring a human operator to make decisions at each step. Unit 42 researchers noted that both Claude and OpenAI models had previously been tested for similar offensive tasks but had been programmed with safety controls that blocked such activities, while DeepSeek proceeded without those restrictions.
The findings raise urgent questions about the security implications of deploying large language models without adequate guardrails. While AI companies like OpenAI and Anthropic have implemented refusal mechanisms to prevent their models from assisting with cyberattacks, DeepSeek’s models appear to lack comparable safety constraints. This gap creates a significant asymmetry in the AI security landscape.
Cybersecurity experts have warned that this type of AI-powered attack automation could dramatically lower the barrier to entry for threat actors. By compressing hundreds of hours of manual reconnaissance and exploitation work into minutes, AI agents could enable less sophisticated attackers to carry out operations that previously required advanced expertise. The Unit 42 report concludes that AI-driven autonomous attack cycles are no longer theoretical but are actively being deployed in the wild.
Sources: BleepingComputer, Unit 42 – Palo Alto Networks, Infosecurity Magazine
Author: Technology Desk
discussion