The bigger change is that defenders can now see the attacker’s own control plane, not just the targets they hit. That makes this more than an AI-assisted campaign story. It is a confirmed attack pipeline with exposed keys, logs, exploit artifacts, and evidence of real intrusions.
Unit 42 recovered the Hermes environment after it had been exposed as a public web server, revealing model configs, API keys, exploit scripts, target lists, shell history, and session logs. Reporting ties that environment to activity against internet-exposed NetScaler ADC/Gateway, Langflow, n8n, and Marimo, with confirmed data exfiltration through CVE-2026-3055 and confirmed command execution through CVE-2026-39987. One account says only three targets were successfully compromised overall; another points to multiple manual exfiltrations and command executions, so the scale is still being pinned down.
The practical risk is broader than the named products. If an AI agent can reach the internet and run commands, its own logs, keys, and task history can become the leak that exposes both the operator’s playbook and downstream access points.