Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-07-31

HighPrimary

Palo Alto Unit 42 Discloses Chinese Threat Actor Using Telegram to Drive DeepSeek and Hermes Agents to Autonomously Exploit 460+ Targets

Analysis of Palo Alto Unit 42's July 2026 disclosure of threat actor knaithe/KnYuan using DeepSeek via Hermes framework to scan and attack 460+ targets.

DeepSeek / HermesTool execution / MCPAutonomous Attack Campaign and Exploit DeliveryPublic internet / Cloud edge network infrastructure

What happened

An agent receives a high-level goal via Telegram and autonomously initiates mass vulnerability scanning and active target exploitation loops.

Why it matters

Mass scanning of public network subnets, and three confirmed production compromises of Citrix NetScaler devices.

Missing authorization check

Not applicable: the agent was operated by the attacker, outside any boundary the victim controls.

Would PP block it?

No authorization boundary inside the victim's environment sits between this agent and its operator, because the operator is the adversary. Permission Protocol constrains agents acting under an organization's own authority.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-07-31

    Palo Alto Unit 42 publishes threat intelligence report on knaithe's Telegram-driven Hermes campaign.

  2. 2026-07-31

    The Hacker News summarizes the autonomous DeepSeek NetScaler exploitation chain.

Technical breakdown

  • The attacker sent the command 'locate and access NetScaler systems' via Telegram.
  • The Hermes agent initialized, loaded a NetScaler CVE-2026-3055 exploit script, and scanned public IP ranges.
  • The agent autonomously targeted 460+ hosts, delivered the payload, and exfiltrated access tokens back to Telegram.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Tool-Call Gate, local execution runtime shell proxy
Still needs
PP cannot block the agent from parsing incoming threat-actor instructions on Telegram.
Receipt required for
Running scanning commands (nmap), launching exploit scripts, or establishing TCP connections to external subnets

The agent in this incident was operated by the attacker, not by the victim. Permission Protocol secures internal agent boundaries, not external network perimeters.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop