A threat actor based in Zhuhai wired DeepSeek into an open-source agent framework called Hermes, then piloted the whole setup via Telegram to attack hundreds of internet-facing systems. Palo Alto Networks' Unit 42 published the analysis on August 2. Here's what matters: it's not an edge case.

Source: [Dev.to](https://dev.to/peremptory/a-threat-actor-used-deepseek-to-orchestrate-460-attacks-via-telegram-2jpi)

Sponsored