Public CVEs are no longer just a patching problem. An attacker can hand discovery, exploit search, and target switching to an agent and get machine-speed retries after a failed first hit, which lowers the skill and time needed to weaponize disclosed flaws.
Unit 42 says a Chinese-speaking actor, using DeepSeek through Hermes Agent and several other LLMs, autonomously enumerated targets, pulled public proof-of-concepts, and pivoted across seven disclosed CVEs. The activity touched Langflow, n8n, Apache Tomcat, Palo Alto Networks PAN-OS, Citrix NetScaler ADC/NetScaler Gateway, and marimo, with confirmed impact.
The practical change is speed and persistence across product families. A failed exploit no longer ends the campaign if the operator is an agent that can keep searching adjacent CVEs and try again without waiting on a human.