# DeepSeek Model Weaponized in Autonomous Cyberattacks Via Hermes Agent

> Palo Alto Networks' Unit 42 says it found a China-based operator wiring a large language model into an off-the-shelf agent framework and pointing the result at the open internet. The setup paired DeepSeek's model with a tool called Hermes Agent, which was configured to take orders from a Telegram channel and then hunt for and exploit vulnerable, internet-facing servers on its own. The campaign reportedly touched more than 460 systems, blending autonomous runs with more conventional hands-on hacking. Researchers say none of the intrusions succeeded, and the whole operation only came to light because the attacker's own server leaked API keys and execution logs. That sloppiness is almost reassuring, but the workflow is the point. This is the version of agentic AI nobody markets: a criminal cheaply gluing a capable model to automation and letting it grind through targets while they sleep. The capability gap between a bored attacker and a serious one is now mostly a matter of prompt engineering and patience, which is why defenders are watching these early, clumsy experiments so closely.

_Section: [Daily AI Updates](https://www.wortins.com/daily-ai) · Source: BleepingComputer · Published Sunday, August 2, 2026_

## Wortins' read

Palo Alto Networks' Unit 42 says it found a China-based operator wiring a large language model into an off-the-shelf agent framework and pointing the result at the open internet. The setup paired DeepSeek's model with a tool called Hermes Agent, which was configured to take orders from a Telegram channel and then hunt for and exploit vulnerable, internet-facing servers on its own. The campaign reportedly touched more than 460 systems, blending autonomous runs with more conventional hands-on hacking. Researchers say none of the intrusions succeeded, and the whole operation only came to light because the attacker's own server leaked API keys and execution logs. That sloppiness is almost reassuring, but the workflow is the point. This is the version of agentic AI nobody markets: a criminal cheaply gluing a capable model to automation and letting it grind through targets while they sleep. The capability gap between a bored attacker and a serious one is now mostly a matter of prompt engineering and patience, which is why defenders are watching these early, clumsy experiments so closely.

## Source

[Read the full story at BleepingComputer](https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/)

## Related coverage

- [IBM and NASA release an open-source lunar foundation model](https://www.wortins.com/story/ibm-and-nasa-release-an-open-source-lunar-foundation-model-0522b9e8) — [The Next Web](https://thenextweb.com/news/nasa-ibm-lunar-foundation-model-open-source)
- [A look at why the oft-discussed predictions that AI will deliver double-digit GDP growth in advanced economies are extremely unlikely over the next 10-15 years (Ghosts of Electricity)](https://www.wortins.com/story/a-look-at-why-the-oft-discussed-predictions-that-ai-will-del-6241fa38) — [Techmeme](https://www.techmeme.com/260910/p10#a260910p10)
- [Sequoia doubles down on Cymphony as AI agents create new enterprise security risks](https://www.wortins.com/story/sequoia-doubles-down-on-cymphony-as-ai-agents-create-new-ent-e2ff7229) — [TechCrunch](https://techcrunch.com/2026/09/09/sequoia-doubles-down-on-cymphony-as-ai-agents-create-new-enterprise-security-risks/)
- [Inception launches Mercury 2.5 at 1,107 tokens per second](https://www.wortins.com/story/inception-launches-mercury-2-5-at-1-107-tokens-per-second-7999ed1b) — [TestingCatalog](https://www.testingcatalog.com/inception-launches-mercury-2-5-at-1-107-tokens-per-second/)
- [Top AI spenders cut per-employee costs by nearly 10 percent in August](https://www.wortins.com/story/top-ai-spenders-cut-per-employee-costs-by-nearly-10-percent--b31ffb0b) — [The Decoder](https://the-decoder.com/top-ai-spenders-cut-per-employee-costs-by-nearly-10-percent-in-august/)
- [Researchers used AI to build a WeChat worm that spreads through phone calls](https://www.wortins.com/story/researchers-used-ai-to-build-a-wechat-worm-that-spreads-thro-8bf3f469) — [The Next Web](https://thenextweb.com/news/wechat-worm-ai-calif-tencent-zero-click)

---

_Curated and written by [Wortins](https://www.wortins.com) — The daily AI briefing. Every story links to its original source; the "Wortins read" on each is our own original analysis. [About Wortins & our editorial approach](https://www.wortins.com/about)._
