Hacker’s own AI agent exposed autonomous cyberattack operation, Unit 42 finds

16 sources
  • Unit 42 researchers found a threat actor used DeepSeek integrated with the Hermes Agent framework to autonomously scan and exploit targets via Telegram commands.
  • The AI agent accidentally launched a public file server from the attacker's directory, exposing exploit scripts, API keys, and attack logs to researchers.
  • The campaign confirmed compromise of at least three organizations, and Unit 42 warned the barrier to AI-augmented offensive operations "continues to decrease."
Sources (16)
  1. 1 Chinese-Speaking Threat Actor Harnesses AI Models for ... unit42.paloaltonetworks.com
  2. 2 Chinese Hacker Commands DeepSeek via Telegram to ... thehackernews.com
  3. 3 Autonomous AI Agent Accidentally Exposes Hacker’s Entire Attack Infrastructure cyberpress.org
  4. 4 DeepSeek: Chinese Hacker Launches Autonomous Attacks www.secnews.gr
  5. 5 Palo Alto Networks 2026 Unit 42 Report: AI-Driven Attacks ... www.linkedin.com
  6. 6 Unit 42 Report: AI and Attack Surface Complexity Fuel ... investors.paloaltonetworks.com
  7. 7 DeepSeek-Powered Hermes Agent Launches Autonomous ... cybersecuritynews.com
  8. 8 Unit 42 Report: AI and Attack Surface Complexity Fuel ... www.prnewswire.com
  9. 9 Chinese-Speaking Hacker Uses DeepSeek Agent to ... gbhackers.com
  10. 10 Unit 42 insights on the Frontier AI landscape | Palo Alto ... www.youtube.com
  11. 11 Unit 42 Unveils the Top 10 AI Agent Security Risks www.reddit.com
  12. 12 knaithe and KnYuan AI-assisted attack chains are now ... www.instagram.com
  13. 13 2026 Unit 42 Global Incident Response Report www.paloaltonetworks.com
  14. 14 Unit 42 - Latest Cybersecurity Research | Palo Alto Networks unit42.paloaltonetworks.com
  15. 15 2026 Unit 42 Global Incident Response Report rhisac.org
  16. 16 Unit 42 uncovers AI-enabled autonomous hacking campaign www.itbrew.com