A hacker sent one instruction over Telegram

The AI agent took it from there — no human clicked another button for the rest of the operation.

Unit 42 tracked "knaithe" (aka KnYuan), a Zhuhai-based operator who wired DeepSeek into the open-source Hermes Agent framework and let it run reconnaissance and exploitation autonomously against 460+ internet-facing targets.

WHAT ACTUALLY HAPPENED

Knaithe connected DeepSeek to Hermes Agent, gave it one starting instruction via Telegram, and stepped back. The agent scanned for internet-facing systems, matched them to public exploits, and launched attacks on its own — no further operator input was logged.

Unit 42 documented seven exploit tracks spanning eight CVEs (one chain combined two vulnerabilities). In parallel, the same actor ran manual attacks: stealing data from three organizations via a NetScaler flaw and compromising 11 exposed Marimo notebook servers.

The operation surfaced by accident. Hermes Agent spun up a Python HTTP server to stage its haul, publicly exposing the stolen data — the mistake that led researchers back to knaithe.

WHY THIS CHANGES THE MATH

This is not a proof-of-concept. It's a documented autonomous attack chain that ran against real organizations at scale, on infrastructure anyone can rent and a model anyone can access. The barrier to running a reconnaissance-through-exploitation campaign dropped from "skilled operator with time" to "one Telegram message."

Your exposure window used to be measured against human attacker bandwidth. That assumption no longer holds.

WHAT TO DO NOW

INVENTORY YOUR INTERNET-FACING SURFACE — knaithe's agent found targets by scanning first. If you don't know what's exposed, an autonomous scanner will find it before you do.

PATCH ON DAYS, NOT WEEKS — the exploited flaws, including NetScaler, were already public. Agentic actors weaponize known CVEs faster than manual patch cycles keep up.

WATCH FOR MACHINE-SPEED RECON PATTERNS — rapid, sequential probing across unrelated CVEs from a single source is a signature agentic tooling leaves behind; tune detection for it.

AUDIT OUTBOUND EXPOSURE OF DEV TOOLS — Marimo servers and notebook environments are frequently exposed by default; treat them as production assets, not internal scratch space.

The next campaign against your organization might not have a human operator watching it happen in real time.

Is your detection stack built to catch a human attacker, or an autonomous one?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.