Palo Alto Networks' Unit 42 documented a Chinese-speaking operator, tracked as 'knaithe', who wired DeepSeek into the open-source Hermes Agent framework and steered it with Telegram messages. After an initial instruction, the agent autonomously found internet-facing systems, pulled public exploit code from GitHub and attempted to exploit them — but every autonomous attempt failed, because the targets required authentication the exploits could not supply. The confirmed damage across the campaign's 460-plus targets came from the operator's own manual attacks: data stolen from three Citrix NetScaler servers and commands executed on eleven Marimo notebook endpoints. The operation came to light when the agent mistakenly launched a file server from the operator's home directory, exposing API keys, exploit scripts and full attack logs. (Correction: an earlier version of this story implied the three confirmed breaches were the autonomous agent's work. Unit 42 attributes them to manual attacks and reports that the autonomous campaigns compromised none of their targets.)