Morning Edition · Wednesday, August 12, 2026Published at 1:04 AM EDT · New York
Researchers at Palo Alto Networks documented a separate campaign in which a Chinese-speaking attacker used the DeepSeek model to run intrusions with little human supervision, and said that operator appeared to be independent of any state.

The Financial Times reports that China-linked hackers attacked Taiwan using artificial-intelligence agents that carried out reconnaissance and intrusions simultaneously, which it describes as a new phase of cyberwarfare.
Attribution is where accounts differ. Palo Alto Networks' Unit 42 documented a Chinese-speaking operator using several large language models to automate attacks on internet-facing systems, and said it believed that attacker was independent rather than state-supported. The researchers found the operation only because the attacker's own agent misconfigured a file server and exposed the infrastructure.
The technical detail matters more than the label. Help Net Security reported that the operator used the Hermes Agent framework with the Chinese model DeepSeek as its reasoning engine, enumerating vulnerabilities, downloading public exploit code and attempting intrusions without human direction. In one recovered session, the agent targeted a flaw in the Langflow software rated 9.8 out of 10 for severity and identified 84 exposed servers, then failed because the required configuration was not present.
An attack that once required a trained team can now be run by one person renting inference capacity. That changes the volume of attempts far more than it changes the sophistication of any single one.
Cybersecurity vendors and the case for export controls on Chinese models, since a Chinese model named as the reasoning engine supports both security budgets and restrictions on DeepSeek.
Two different claims are stacked here: Unit 42 documented an individual Chinese-speaking operator it assessed as unaffiliated with any state, attacking more than 460 hosts across Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka and Taiwan, so the separate framing of state-directed China-linked agents striking Taiwan is not established by that evidence, and the agent's most consequential attempt failed.
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
Automating reconnaissance sharply reduces the cost of the most labor-intensive part of an intrusion, so the number of attempts against exposed infrastructure rises even if success rates do not. Defenders in finance, utilities and semiconductor manufacturing carry that cost through higher security spending and, eventually, higher cyber insurance premiums. Taiwan is the most exposed case because its chip supply chain is a single point of failure for global electronics, and any confirmed disruption there directly affects hardware pricing and delivery schedules.
Synthesized from: Financial Times · Palo Alto Networks Unit 42 · Help Net Security
Start a discussion in Townsquare.
More from this edition
What to watch
Observations to monitor, not financial advice.
Comments
0No comments yet.