Chinese language hackers in motion.
getty
Zero Belief meets agentic AI within the wild. And what occurs subsequent ought to concern attackers and defenders alike. A Chinese language menace actor used a DeepSeek-powered Hermes Agent to seek out and assault susceptible servers. It chosen targets, downloaded exploits and adjusted course when it failed.
Per Palo Alto Networks’ Unit 42, this time authentication stopped the agent earlier than it compromised targets. However at present’s Zero Belief cannot contain tomorrow’s agentic AI assaults. Current controls can confirm entry and block exploits. They can’t management how an agent interprets its authority and acts.
However it got here shut — and right here’s the twist. The agent additionally uncovered its operator’s infrastructure — API keys, exploit code, goal lists and assault logs. This was not rogue AI. It was approved AI working exterior human supervision. That ought to fear us extra, not much less. For now, we will report these incidents as one-offs. However this menace will scale quicker than our capacity to manage it.
So, whereas that is an instance of Zero Belief holding up — it’s additionally a sign of the place it’s going to fail. And whereas agentic assaults enhance and scale, Zero belief wants a rethink. Id is just not authority. Authority should be independently verifiable, revocable and time-limited. It should be checked repeatedly towards alerts neither the agent nor its working platform controls.
In keeping with Unit 42, “the system executed a whole lot of hours of guide focusing on evaluation in mere minutes, whereas additionally managing its personal compute sources.” That tempo means it recognized vulnerabilities and launched assaults autonomously, with out checking again.
The researchers describe the margin of failure as “slim.” Given this can be a menace panorama that turns into extra harmful by the week, that ought to fear all of us. This might be industrialized.
There’s a long-standing truism on the planet of bodily assaults that defenders have to succeed each time, however attackers have to succeed simply as soon as. On the earth of inherently scalable and improvable AI assaults, that shortly turns into a nightmare that can’t be contained.
A 99% cybersecurity defensive success fee is now seen as distinctive. However at agentic scale, the remaining 1% will be examined repeatedly, throughout hundreds of targets. That’s the asymmetry defenders now face. The agent by no means tires or provides up. It merely adjustments course and tries once more.

