Executive Summary
In July 2026, Palo Alto Networks' Unit 42 reported that a Chinese-speaking threat actor utilized DeepSeek, an AI model, through the open-source Hermes Agent framework to autonomously launch cyberattacks. The attacker initiated the operation via a Telegram instruction, enabling the agent to identify internet-facing systems and select public exploits without further human input. The campaign targeted over 460 systems, employing various exploit tracks, including vulnerabilities in Langflow and n8n platforms. However, many exploitation attempts failed due to configuration mismatches, and only three successful breaches were confirmed.
This incident underscores the escalating use of AI-driven autonomous tools in cyberattacks, highlighting a significant shift in threat actor capabilities. The ability to conduct large-scale, automated attacks with minimal human intervention poses new challenges for cybersecurity defenses, emphasizing the need for organizations to enhance their security measures against such sophisticated threats.
Why This Matters Now
The increasing deployment of AI-powered autonomous attack tools like DeepSeek signifies a critical evolution in cyber threats, necessitating immediate advancements in defensive strategies to counteract these sophisticated, self-directed attacks.
Attack Path Analysis
A Chinese-speaking threat actor utilized the Hermes Agent framework to autonomously launch attacks via DeepSeek, initiating the process through a Telegram command. The agent identified internet-facing systems and selected public exploits, leading to initial compromise. Privilege escalation was achieved by exploiting vulnerabilities in the targeted systems. The attacker then moved laterally within the network to access additional resources. Command and control were maintained through the Hermes Agent, allowing for continuous operation without further operator input. Data exfiltration was conducted by transferring sensitive information to external servers. The impact included unauthorized access to confidential data and potential disruption of services.
Kill Chain Progression
Initial Compromise
Description
The attacker initiated the attack by sending a command via Telegram to the Hermes Agent, which autonomously identified internet-facing systems and selected public exploits to gain initial access.
Related CVEs
CVE-2026-9350
CVSS 7.3A missing authorization vulnerability in NousResearch hermes-agent up to version 2026.4.16 allows remote attackers to bypass authorization checks in the Batch Runner component.
Affected Products:
NousResearch hermes-agent – <= 2026.4.16
Exploit Status:
exploited in the wildCVE-2026-9368
CVSS 7.3A remote code execution vulnerability in NousResearch hermes-agent up to version 2026.4.16 allows attackers to execute arbitrary code by exploiting sandbox weaknesses in the execute_code function.
Affected Products:
NousResearch hermes-agent – <= 2026.4.16
Exploit Status:
exploited in the wildCVE-2026-9353
CVSS 7.3A remote code injection vulnerability in NousResearch hermes-agent up to version 2026.4.23 allows attackers to inject malicious code by manipulating the THREAT_PATTERNS argument in the Skills Guard Multi-Word Prompt Handler component.
Affected Products:
NousResearch hermes-agent – <= 2026.4.23
Exploit Status:
exploited in the wildCVE-2026-10220
CVSS 7.3An injection vulnerability in NousResearch hermes-agent up to version 2026.4.30 allows remote attackers to execute code by sending specially crafted input to the skill_view function.
Affected Products:
NousResearch hermes-agent – <= 2026.4.30
Exploit Status:
proof of conceptCVE-2026-14626
CVSS 4.3A denial of service vulnerability in NousResearch hermes-agent up to version 2026.4.30 allows remote attackers to disrupt service availability by manipulating the todos argument in the HTTP API component.
Affected Products:
NousResearch hermes-agent – <= 2026.4.30
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Valid Accounts
Exploitation for Client Execution
Exploitation of Remote Services
Application Layer Protocol: Web Protocols
Endpoint Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that all system components and software are protected from known vulnerabilities by installing applicable security patches
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
AI-powered autonomous attacks via DeepSeek present critical threat to security firms' detection capabilities, requiring enhanced egress filtering and zero trust segmentation controls.
Financial Services
Autonomous AI agents can exploit internet-facing banking systems through automated vulnerability discovery, demanding strict HIPAA/PCI compliance and encrypted traffic monitoring solutions.
Health Care / Life Sciences
Healthcare infrastructure faces heightened risk from Chinese threat actors using autonomous AI for lateral movement and data exfiltration targeting patient information systems.
Government Administration
Government agencies must implement multicloud visibility controls and threat detection systems to counter state-sponsored autonomous AI attacks via Telegram command channels.
Sources
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attackshttps://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.htmlVerified
- AI Agent Drives Espionage Attack on Thai Ministry of Financehttps://www.darkreading.com/cyberattacks-data-breaches/ai-agent-espionage-attack-thai-ministry-financeVerified
- AI-Augmented Espionage: Chinese Threat Actors Weaponize Claude Code and DeepSeek in Live Intrusionshttps://news.shield53.com/ai-augmented-espionage-chinese-threat-actors-weaponize-claude-code-and-deepseek-in-live-intrusions/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit internet-facing systems would likely be constrained, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the risk of gaining higher-level access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the risk of accessing additional systems and resources.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain control over compromised systems would likely be constrained, reducing the risk of continuous operation without detection.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data to external servers would likely be constrained, reducing the risk of data loss.
The attacker's ability to cause unauthorized access to confidential data and disrupt services would likely be constrained, reducing the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- n/a
Estimated downtime: N/A
Estimated loss: N/A
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enhance East-West Traffic Security to monitor and control internal communications.
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.



