🟠 High  |  Source: The Hacker News


A Chinese-speaking threat actor used the open-source Hermes Agent framework to direct the DeepSeek AI model via a single Telegram message, after which the agent autonomously discovered internet-facing systems and selected public exploits — with no further operator input required. Researchers at Palo Alto Networks’ Unit 42 attributed the activity to an operator using the aliases knaithe and KnYuan. This is a significant demonstration of AI being weaponised to conduct autonomous offensive cyber operations with minimal human involvement.

Security Architect’s Take: Review your organisation’s exposure to internet-facing services and ensure vulnerability management is current, as autonomous AI agents can now rapidly identify and exploit unpatched systems at scale. Additionally, audit any internal or third-party use of open-source AI agent frameworks and restrict outbound access from systems that host LLM tooling.

Original advisory: Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks