What happened
An agent receives a high-level goal via Telegram and autonomously initiates mass vulnerability scanning and active target exploitation loops.
2026-07-31
HighPrimaryAnalysis of Palo Alto Unit 42's July 2026 disclosure of threat actor knaithe/KnYuan using DeepSeek via Hermes framework to scan and attack 460+ targets.
What happened
An agent receives a high-level goal via Telegram and autonomously initiates mass vulnerability scanning and active target exploitation loops.
Why it matters
Mass scanning of public network subnets, and three confirmed production compromises of Citrix NetScaler devices.
Missing authorization check
Not applicable: the agent was operated by the attacker, outside any boundary the victim controls.
Would PP block it?
No authorization boundary inside the victim's environment sits between this agent and its operator, because the operator is the adversary. Permission Protocol constrains agents acting under an organization's own authority.
Incident analysis
2026-07-31
Palo Alto Unit 42 publishes threat intelligence report on knaithe's Telegram-driven Hermes campaign.
2026-07-31
The Hacker News summarizes the autonomous DeepSeek NetScaler exploitation chain.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
The agent in this incident was operated by the attacker, not by the victim. Permission Protocol secures internal agent boundaries, not external network perimeters.
Related incidents and controls
Start small
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.