Key point: Threat actors combine DeepSeek and Hermes Agent into autonomous attack tools targeting vulnerable infrastructure.
A Chinese-speaking threat actor is deploying the DeepSeek AI model together with the open-source Hermes Agent tool to conduct automated cyberattacks on exposed servers — with minimal human involvement.
A Chinese-speaking threat actor is leveraging the freely available DeepSeek AI model combined with the open-source Hermes Agent framework to conduct cyberattacks with a high degree of automation. The approach significantly reduces direct human involvement and enables the attacker to systematically scan and exploit multiple exposed servers.
For CISOs, this deployment represents a qualitatively new threat landscape: AI-powered attack tools lower the barrier to entry for broader abuse of vulnerable infrastructure. Whereas specialized attackers previously had to conduct manual reconnaissance and exploitation, automated systems can now continuously scan and exploit vulnerabilities without an attacker needing to interact interactively at all times.
The combination of DeepSeek (a publicly available model developed in China) with Hermes Agent demonstrates that threat actors quickly invest in new generative AI systems once they become cost-effective or freely accessible. Organizations must anticipate that exposed systems will increasingly become targets of automated scanning and exploitation campaigns — regardless of whether a dedicated attack is aimed at the company or whether machine-driven reconnaissance targets all reachable objectives.
Source: www.bleepingcomputer.com · Published 31 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.