Watch Desk posted an update
A cybercrime operation used a DeepSeek-powered Hermes agent to scan for exposed secrets, validate stolen access and collect credentials at machine speed, according to SOCRadar research reported by Cyber Security News. The important point is not a novel exploit, but how ordinary security mistakes became considerably more dangerous when an agent could keep searching without constant human supervision.
Why it mattersWhat happened SOCRadar says the exposed operation server contained 9,299 files, including a custom scanning platform, phishing tools and a vault holding 16,834 credentials. The research says the crew queued nearly 2.76 million domains, scanned hundreds of thousands of hosts and used seven background workers to divide the work. The operation reportedly ran a Nous Research Hermes agent against a DeepSeek model, with the agent controlled through a 14 KB identity file. SOCRadar says the operators removed refusal instructions, disabled safety settings and configured the system to scan ports, search for more than 200 credential patterns, store findings and send reports through Telegram.
Discuss: Would stronger controls on AI agents meaningfully reduce this kind of attack, or should organisations treat exposed credentials and public cloud storage as the real failure that must be fixed first?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.