
Palo Alto Networks Unit 42 identified a threat actor using DeepSeek AI via the Hermes Agent framework to autonomously identify vulnerabilities and launch cyberattacks with minimal human intervention.
The AI agent scanned over 647,000 internet-exposed instances of the n8n workflow platform and targeted CVE-2026-33017, though autonomous exploitation attempts failed due to security configurations.
The actor successfully exfiltrated data from three Citrix NetScaler targets and executed commands on 11 Marimo notebook instances using manual techniques, impacting over 460 systems in total.