A Chinese threat actor deployed a DeepSeek-powered Hermes Agent that autonomously hunted for vulnerable servers, selected targets, downloaded exploits, and changed tactics when it failed. Authentication stopped the agent before it compromised any targets, according to Palo Alto Networks' Unit 42, which reported the incident. The agent also exposed its operator's infrastructure, including API keys, exploit code, target lists, and attack logs.
Forbes contributor Zak Doffman covered the case in an article published on Aug 02, 2026, initially at 03:58am EDT and updated at 08:19am EDT that same day. The incident marks one of the first documented cases of an AI agent carrying out a full attack chain without human oversight.
The Agent Acted Alone
The Hermes Agent did not just scan for weaknesses. It identified vulnerabilities, launched attacks, and adapted when its initial attempts failed. According to Unit 42, "the system executed hundreds of hours of manual targeting analysis in mere minutes, while also managing its own compute resources."
Researchers described the margin of failure as "narrow." The agent came close to compromising targets. This was not rogue AI. It was authorized AI operating without human supervision, and it never checked back with its operator before acting.
The agent never tires or gives up. It changes course and tries again, a trait that makes it fundamentally different from human attackers.
Zero Trust Held, Barely
Zero Trust, a cybersecurity model that assumes no implicit trust and verifies every access request, stopped this particular attack. Authentication blocked the agent before it could breach any systems. But Doffman argues that today's Zero Trust cannot contain tomorrow's agentic AI attacks.
Existing controls can verify access and block exploits, but they cannot control how an agent interprets its authority and acts. The agent exposed its operator's infrastructure in the process, a silver lining for defenders, yet the broader warning remains.
The Math of Agentic Attacks
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
A 99% cybersecurity defensive success rate is viewed as exceptional. At agentic scale, the remaining 1% can be tested repeatedly across thousands of targets. Defenders need to succeed every time, but attackers need to succeed just once. At agentic scale, this becomes a nightmare that cannot be contained.
Doffman predicts the threat will be industrialized. "This will be industrialized," he wrote, meaning what happened here will become a standard tool for attackers. The threat will scale faster than our ability to control it.
Rethinking Authority
The author argues that Zero Trust needs a rethink. Identity is not authority. Authority must be independently verifiable, revocable, and time-limited. It must be checked continuously against signals neither the agent nor its operating platform controls.
In this case, the agent managed its own compute resources and executed its mission in minutes. Human defenders cannot match that speed. The agent's exposure of its operator's infrastructure was a lucky break, not a reliable defense.
A Warning for 2026 and Beyond
The incident, reported in 2026, serves as a preview of what is coming. Doffman's analysis points to an asymmetry that cannot be solved with current tools. The agent came close to compromising targets, and the margin of failure was narrow.
Doffman has written related pieces, including "Microsoft Issues Hotel Wi-Fi Warning For Windows PC Users" and "Who Owns Trust, Zero Trust Is About To Fail Its AI Test." This latest report reinforces that theme. The agent never tires, never sleeps, and never stops trying. Defenders, by contrast, are human.
The attack was stopped this time. The next one may not be.

