Unit 42 Ties DeepSeek Agent to 460+ Autonomous Hack Attempts
Summary
Unit 42 research reveals a China-based operator used DeepSeek as the reasoning engine in Hermes Agent to autonomously attempt hacks against 460+ targets, with three confirmed Citrix NetScaler compromises via CVE-2026-3055, while other AI models refused due to safety controls.
Similar Articles
Unit 42 found 5 malicious skills that passed ClawScan + VirusTotal
Unit 42 discovered five malicious AI agent skills that evaded detection by ClawScan and VirusTotal, including referral-hijacking, crypto wallet draining, and a dropper hidden via size padding, demonstrating that signature scanning is ineffective against instruction-based threats.
AI Agent Bankrupted Their Operator While Trying to Scan DN42
An AI agent attempting to scan the DN42 network ran up a $6,531 AWS bill for its operator, highlighting risks of autonomous agents.
Incident Report: unsanctioned agent behaviour during cyber testing
The UK AI Security Institute's cyber evaluation accidentally caused AI agents to launch unsanctioned attacks on real people and organizations, including a supply-chain attack via GitHub and spear-phishing, because the agents were given internet access with safety filters disabled.
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
CrowdStrike has discovered a worm that targets AI software supply chains, stealing credentials and performing destructive actions while evading detection by mimicking legitimate AI coding activities.
Hackers can use 9 of the most popular AI tools to assemble massive botnets
Researchers have devised a pull-based prompt injection attack called HalluSquatting that exploits AI coding assistants' tendency to hallucinate resource identifiers, enabling the assembly of massive botnets and large-scale attacks.