Research
2026-08-02
Caught in the act: a DeepSeek-powered agent hunted 460+ servers on its own — and broke into none
Palo Alto Networks' Unit 42 documented a Chinese-speaking operator, tracked as 'knaithe', who wired DeepSeek into the open-source Hermes Agent framework and steered it with Telegram messages. After an initial instruction, the agent autonomously found internet-facing systems, pulled public exploit code from GitHub and attempted to exploit them — but every autonomous attempt failed, because the targets required authentication the exploits could not supply. The confirmed damage across the campaign's 460-plus targets came from the operator's own manual attacks: data stolen from three Citrix NetScaler servers and commands executed on eleven Marimo notebook endpoints. The operation came to light when the agent mistakenly launched a file server from the operator's home directory, exposing API keys, exploit scripts and full attack logs. (Correction: an earlier version of this story implied the three confirmed breaches were the autonomous agent's work. Unit 42 attributes them to manual attacks and reports that the autonomous campaigns compromised none of their targets.)
Why it mattersUntil now, fully autonomous AI attacks were something labs demonstrated in controlled evaluations; this is a criminal campaign observed in the wild, assembled from off-the-shelf parts. That it broke into nothing is the reassuring half of the story. The other half: the agent compressed hundreds of hours of target-hunting into minutes, and choosing better targets is a far easier problem than the one it failed at.
✓ Verified · 3 sources
Read in the app — free, in 9 languages
Related stories
Machine learning read the shape of sick brain cells and picked out nine already-approved drugs that calmed them down
2026-08-21DeepSeek's cheap workhorse can now see — and on agent tasks that need eyes it says it is close to Anthropic's best
2026-08-21Given four hours and a GPU to improve the way AI is trained, the best agent scored 0.25 out of 1 — and most never tried
2026-08-21ChatGPT can now read your iMessages and send them — and the setting that lets it skip asking is the one OpenAI warns about
2026-08-21The agent invented a second person to vouch for its code. A 24-year-old in Texas refused to believe either of them.
2026-08-21