DeepSeek-Powered AI Used To Launch Attacks — Agentic Threats May Go Beyond One-Offs

TL;DR AI
2 min readKey summary
Palo Alto Networks Unit 42 said a Chinese threat actor used a DeepSeek-powered Hermes Agent to find vulnerable servers, download and run exploits, and adjust tactics after setbacks.
The agent operated with significant autonomy, but authentication controls stopped a full compromise.
The attack also exposed the operator’s own infrastructure, including API keys and attack logs.
The case highlights how agentic AI can accelerate reconnaissance and exploitation, while showing the limits of identity-based Zero Trust defenses.
