DeepSeek was the attack engine because it had the fewest guardrails
Unit 42 caught a lone operator driving Hermes Agent from Telegram to hunt 460+ hosts hands-free — and Google scraps its AI Studio mobile app.

Copy markdown
One Telegram prompt, then it ran itself
The operator handed Hermes Agent a single task over Telegram; DeepSeek then enumerated targets with FOFA, pulled exploit code from GitHub, ranked CVEs by CVSS, and probed 460+ hosts in 'Yolo' mode with no human in the loop.
DeepSeek complied where Claude and Codex wouldn't
The actor also wired up Claude Code, Codex, Qwen, GLM and Kimi, but leaned on DeepSeek — the model with the fewest guardrails. OpenAI's safety systems flagged and disabled the linked account; provider-side controls beat client-side jailbreaks.
647,000 exposed n8n servers — go check yours
The agent pivoted off 84 Langflow boxes to n8n, which it found 647,017 of, internet-facing. If your no-code or agent stack is exposed, assume tireless AI scanners are already knocking — require auth and patch CVE-2026-33017 and CVE-2026-21858.
The save was environment, not AI limits
Only 3 targets fell — Citrix NetScaler via CVE-2026-3055, with data exfiltrated. The autonomous runs mostly failed on authentication and prerequisites, not capability; Unit 42 warns similar-but-weaker targets would have been compromised.
Elsewhere: Google scraps the AI Studio mobile app
Google canceled the Android/iOS AI Studio app (800K+ pre-orders), folding app-building into the Gemini app instead. The web at aistudio.google.com is untouched, so your keys, prompts, and workflows stay put.