Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek via the open-source Hermes Agent framework, instructed over Telegram, to launch autonomous attacks. The agent scanned for internet-facing systems, selected public exploits, and was intercepted while attempting to compromise 1,200+ hosts for proxyjacking.
2 sources
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- SCAIL 2 fan video replaces GTA 6 characters with fat versions
- State machine guardrails govern agent tool use in Claude Code, Cursor
- Hollywood-style racing trailer built with ComfyUI, LTX 2.3 & Krea 2
- Ethan Mollick: Microsoft and Google were daring with early AI
- Scoble: AI reads feet via video camera, no LiDAR