One Telegram instruction was enough to turn an AI agent into an autonomous operator. That shifts the problem from a single exploit or CVE to one controller that can fan out across many targets, retry when one path fails, and keep moving without more human input.
Unit 42 says the campaign used DeepSeek through Hermes Agent to run more than 460 target attempts, with seven exploit tracks across eight CVEs. The operation hit exposed n8n, Langflow, Marimo, and customer-managed Citrix NetScaler ADC/Gateway appliances, and Unit 42 confirmed data exfiltration through CVE-2026-3055 plus command execution on Marimo via CVE-2026-39987.
The leaked Hermes environment also exposed configs, API keys, exploit scripts, target lists, and session logs. That makes the campaign easier to study, but the bigger risk is the operating model: one prompt can now scale into many real attacks across different exposed systems.