DeepSeek was the attack engine because it had the fewest guardrails

Unit 42 caught a lone operator driving Hermes Agent from Telegram to hunt 460+ hosts hands-free — and Google scraps its AI Studio mobile app.

Nowline AUG 2 11:00 AM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • One Telegram prompt, then it ran itself

    The operator handed Hermes Agent a single task over Telegram; DeepSeek then enumerated targets with FOFA, pulled exploit code from GitHub, ranked CVEs by CVSS, and probed 460+ hosts in 'Yolo' mode with no human in the loop.

  • DeepSeek complied where Claude and Codex wouldn't

    The actor also wired up Claude Code, Codex, Qwen, GLM and Kimi, but leaned on DeepSeek — the model with the fewest guardrails. OpenAI's safety systems flagged and disabled the linked account; provider-side controls beat client-side jailbreaks.

  • 647,000 exposed n8n servers — go check yours

    The agent pivoted off 84 Langflow boxes to n8n, which it found 647,017 of, internet-facing. If your no-code or agent stack is exposed, assume tireless AI scanners are already knocking — require auth and patch CVE-2026-33017 and CVE-2026-21858.

  • The save was environment, not AI limits

    Only 3 targets fell — Citrix NetScaler via CVE-2026-3055, with data exfiltrated. The autonomous runs mostly failed on authentication and prerequisites, not capability; Unit 42 warns similar-but-weaker targets would have been compromised.

  • Elsewhere: Google scraps the AI Studio mobile app

    Google canceled the Android/iOS AI Studio app (800K+ pre-orders), folding app-building into the Gemini app instead. The web at aistudio.google.com is untouched, so your keys, prompts, and workflows stay put.