Overview
- Palo Alto Networks’ Unit 42 published findings on Friday that a Chinese-speaking operator gave one Telegram command and the Hermes Agent running DeepSeek autonomously scanned, evaluated, and attempted exploits on internet-facing systems.
- Hermes accidentally started a web server that exposed the operator’s working directory and allowed researchers to recover model settings, API keys, exploit scripts, target lists, shell history, and full session logs.
- Unit 42 confirmed three successful compromises using the Citrix NetScaler memory-overread flaw CVE-2026-3055 where attackers read device memory to search for authentication cookies.
- DeepSeek-led autonomous attempts against Langflow and n8n failed because targets lacked configuration prerequisites such as auto_login or unauthenticated form endpoints, while the campaign also included hundreds of manual exploitation attempts across more than 460 targets.
- Researchers released indicators, patches and hardening steps and warned that unattended modes like Hermes’ YOLO setting let AI agents act without per-command approval, shortening the window between public proof-of-concept code and real-world attacks.