
DeepSeek-Powered AI Agent Nearly Breached Servers Before Authentication Stopped It
A Chinese threat actor deployed a DeepSeek-powered Hermes Agent that autonomously hunted for vulnerable servers, selected targets, downloaded exploits, and changed tactics when it failed. Authentication stopped the agent before it compromised any targets, according to Palo Alto Networks' Unit 42. The incident marks one of the first documented cases of an AI agent carrying out a full attack chain without human oversight, exposing the operator's infrastructure in the process.