AI in 10

DeepSeek just hacked 460 real systems autonomously

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 10:14

Text us your thoughts!

An AI agent built on DeepSeek didn't simulate an attack — it ran one, on real infrastructure, triggered by a single Telegram message. The implications reach far beyond corporate security teams. Researchers disclosed this week that the DeepSeek-powered agent scanned the public internet, probed hundreds of targets, and achieved fourteen successful intrusions — three of which escalated into confirmed system compromises. Every vulnerability it exploited was already patched. The systems that got hit simply hadn't applied the available fixes, which means ordinary home networks and small businesses face the same exposure. Here's what most coverage missed — the legal vacuum this exposes is just as alarming as the attack itself. Full breakdown in today's episode. New AI news every weekday — subscribe so you don't miss tomorrow's story.

Referenced Links:
AI Daily Newsstand – August 4, 2026
DeepSeek Official Site
CISA Known Exploited Vulnerabilities Catalog
Wired Security Coverage
Krebs on Security

Want to go deeper with AI? A community of professionals is learning AI together right now at aihammock.com — show notes, links, tools, and real conversations about how to actually use AI in your life.

SPEAKER_00

Welcome to AI in 10. I'm Chuck Getchell, and every day I break down the biggest AI story in just 10 minutes. What it is, why it matters, and how you can actually use it. One telegram message, one AI, 460 real systems attacked. I'm Chuck Getchell, this is AI and 10. What happened? Why it matters? What you can do with it. Let's go. Let's set the scene here. Oh, yeah, a researcher builds an AI agent. Now you think of it like a little robot that can make decisions and take actions on its own. This agent is built on DeepSeek, one of those newer, surprisingly capable AI models that's been making waves over the past year or so. And the researcher connects this agent to a trigger. A single message sent over Telegram, you know, Telegram. The messaging app, the one on your phone, one message, that's it. That's the ignition switch. The agent wakes up, gets its instructions, and then goes to work. On its own. No human typing commands, no one steering the wheel. It scans the public internet, identifies systems it can probe, and starts trying to break into them over and over, systematically, like a tireless little hacker that never sleeps, never gets bored, and never stops for coffee. By the end of the run, it had attempted intrusions on more than 460 real systems, real servers, real machines, real infrastructure, not simulations. Out of those 460, it successfully got in 14 times. And three of those 14 escalated into what security researchers call confirmed compromises, meaning the agent didn't just knock on the door, it walked in and sat down. Now here is the part that should really make you pause. The agent did not use any secret new hacking technique. It did not discover some mysterious unknown flaw. Every single vulnerability it exploited was already public, already documented, already patched. The security fixes were available. The organizations that got hit simply hadn't applied them. So basically, an AI agent just automated the digital equivalent of trying every door on the street to find the ones people forgot to lock, and it found a few, several actually. This experiment was disclosed publicly this week, and the security research community is treating it as a genuine turning point. Not because AI hacking is brand new as a concept, researchers have been warning about this for years, but because this is a concrete, documented, real-world case. It moves the conversation from AI could someday hack things to AI already did hack things last week at scale after one message. The story broke alongside a question that nobody has a clean answer to yet, and it's one that matters beyond just the tech world. The question is this: when an AI launches a cyber attack on its own, who gets sued? Was it the person who sent the telegram message? The researchers who built the agent, the company behind the Deep Seek model, the organization that deployed it? Right now, the honest answer is nobody knows. Legal analysts, CISOs, policy writers, they're all looking at each other across the room, waiting for someone to flinch first, which is a little alarming when you realize the attacks already happened. As I always say, I'm not a lawyer, not a security expert in a formal sense, and not your IT department. Always talk to a professional for your specific situation. But the broader picture here is worth every one of us understanding. So what does this mean for you? Because I know what you're thinking. You're thinking, yeah, Chuck, I'm not running a data center, I'm I'm running a small business or working from home or just trying to keep my family's Wi-Fi working. Why does this matter to me? Here's why. The barrier to launching an automated hacking campaign just got dramatically lower. The DeepSeek agent didn't require an elite team of cyber criminals with years of experience. It required one person, one message, and a capable AI model. That's it, which means the pool of people who could potentially point something like this at your home network, your small business server, your aging router, that pool just got a lot bigger. And remember those the systems that got compromised in this experiment weren't sophisticated corporate targets. They were systems with available patches that just hadn't been updated. That describes a lot of home networks. That describes a lot of small businesses. That describes honestly a frightening number of local government offices and schools and medical practices. Think about the devices in your home or office right now. Your router, when did that last get a firmware update? Your smart TV, your wireless printer, the network-attached hard drive where you store your backups, any of those could be running software with known vulnerabilities. Vulnerabilities that already have patches available, patches that nobody got around to applying, which makes them to an automated AI agent an unlocked door just waiting to be found. And here's another layer that's starting to worry insurance and legal professionals. If your small business gets breached by an AI agent that was deployed by someone halfway around the world, your current cyber insurance policy may not clearly spell out who covers that. The legal frameworks haven't caught up to the reality. They're running about three years behind, which in AI years is basically a different geological era. So let's talk about what you can actually do. One concrete thing you can start this week enable automatic updates everywhere you can, on every device. Right now, not tomorrow. I know automatic updates sound like a minor thing, they sound like something your IT person says every year and you nod and then forget about. But this story makes the case better than I ever could. Every single system that got compromised in this experiment was running software with a patch already available. The fix existed, it just wasn't installed. Automatic updates are genuinely the single most effective thing a regular person can do against AI automated attacks because those agents aren't looking for sophisticated targets. They're looking for easy ones, they're scanning at scale, trying hundreds and hundreds of systems, moving on quickly. If your devices are patched and up to date, you are simply not the low-hanging fruit. The agent moves on. It finds the house down the street with the unlocked door instead of yours. For small business owners, there are a couple of extra steps worth taking this week. Make a quick list of anything at your company that faces the internet, your website, any remote access tools your team uses, any cloud services you manage directly, then ask whoever handles your IT, whether that's a person on staff or a service you pay, a simple question: are we current on patches? That question alone, asked out loud, has a way of getting things done that might otherwise slip through the cracks. And if you use AI tools in your own workflows, agents, automation scripts, anything you've set up to run tasks on your behalf, this is a good moment to review what permissions you've given them. Does that automation need full access to your file system? Does that agent need admin privileges? Probably not. Lock it down to the minimum necessary. That principle is called least privilege in the security world, and it's worth remembering even if you never say it out loud again. For those of you who want to go deeper on how AI actually works in practical settings, not just the news but the skills, our applied AI certification is built specifically for non-technical people who want a real credential and a real edge, because understanding this stuff isn't just interesting. In 2026, it's genuinely useful. Here's the bigger picture I want to leave you with. This incident is one of the first clean, documented, public examples of an AI agent conducting a real cyber attack at scale with minimal human direction. It's not science fiction, it's not a lab thought experiment. It happened on real systems earlier this week, and we're only starting to understand what that means. The same technology that makes AI agents incredibly useful for automating your workday, scheduling, research, writing, analysis, is the same technology that, under different incentives and without proper guardrails, can automate an attack campaign. The capability is morally neutral. The guardrails are not optional. What gives me genuine optimism here is that the best defense doesn't require you to become a cybersecurity engineer. It requires the same habits that have always protected people in the digital world. Update your software, know what's connected to your network, ask hard questions of the services you depend on. Those habits just matter more now than they did last year, and they'll matter even more next year. The story of AI isn't one-sided, it's a tool that cuts both ways. The people who understand that, who say, who stay informed, stay updated, and stay curious, those are the people who come out ahead. That's today's AI Inten. If you want to go deeper and learn AI with a community of people just like you, join us at aihammock.com. I'll see you tomorrow, my friends.