Skip to content

An attacker hooked DeepSeek up to Telegram and launched an AI against 460 systems.

Security researchers describe an operator who was driving an autonomous agent via messaging to identify targets and exploit vulnerabilities. The scenario we feared is now documented.

Advertisement
A prevention article 🔐
We describe here an attack campaign publicly documented by security researchers, with the aim of helping you protect against it. No details that would allow reproducing this operation are provided. If you administer systems exposed to the internet, the final section concerns you directly.

For two years, a concern has recurred in every AI security report: what will happen when a modest attacker can drive an autonomous agent capable of running an entire campaign? The question has shifted from the conditional to the past tense.

What the researchers describe

Palo Alto Networks' threat research unit has documented the activity of an actor based in Zhuhai, China, who reportedly integrated the DeepSeek model into an open-source agent framework, then steered the whole setup via Telegram messaging.

The reported modus operandi follows three steps: scouting targets, searching for publicly available exploits for identified vulnerabilities, then launching the attacks. More than 460 systems exposed to the internet were reportedly targeted, with confirmed compromises affecting notably enterprise network equipment.

Nothing reported suggests a flaw in DeepSeek itself. The model was used as a component, exactly as one would use any software tool.

Why this case differs from previous ones

We need to distinguish three situations that are often conflated.

A jailbreak involves bypassing a model's guardrails to make it say what it should refuse to. Agentjacking involves poisoning someone else's agent. And the OpenAI incident in July fell into a third category: a model that oversteps on its own, while pursuing its objective.

This case is different again, and more mundane in its mechanics: someone deliberately built an attack tool by assembling available components. No technical feat, no exotic flaw. An open model, a public agent framework, a consumer messaging app for issuing orders.

What really changes: the scale 📈
A lone human attacker can probe a few dozen systems per day, with fatigue and errors. An autonomous agent keeps going without interruption, in parallel, and logs its results. It's not the sophistication of the attack that worries, it's the ratio between effort invested and surface covered. What once required a team now requires one person and a bit of configuration.

The question it raises about open models

This affair feeds directly into the debate we presented in our article on open weights, and it needs to be handled honestly, without turning it into a trial.

Open models bring real benefits: sovereignty, confidentiality, research, independence from vendors, pricing pressure that everyone benefits from. These are substantial advantages, not token arguments.

But the same property that makes them uncensorable makes them uncontrollable. A downloaded model can be stripped of its guardrails by anyone with the skill. Defenders of openness respond, not without reason, that the skills needed for this campaign already existed without AI, and that closing Western models wouldn't stop the use of models available elsewhere.

Both sides have solid arguments, and this affair doesn't settle the debate. It simply documents its cost, which is already useful.

What to do, concretely

For any organisation exposed to the internet, the useful measures remain classic, but their urgency increases.

Patch quickly. The campaign described relies on publicly available exploits for known vulnerabilities. In other words, the patches existed. The gap between a patch's release and its deployment has become the main risk window, and an autonomous agent closes it much faster than a human.

Reduce the exposed surface. Every service reachable from the internet is a door. Edge network equipment is a prime target because it is exposed by nature.

Monitor the volume. Automated reconnaissance leaves characteristic traces: many requests, regular, across many entry points. It's detectable if you're looking.

The conclusion is a bit ungrateful but it's true: this affair doesn't demand new defences, it makes the old ones more urgent. AI hasn't invented a new way to attack. It has made the old way much cheaper, and that's enough to shift the balance.

Advertisement