Updated October 2026 to our current guidance. The original reporting date is unchanged.
In July, researchers published the details of a campaign in which a criminal connected an AI to the internet, gave it a task, and let it choose its own targets. Most of the coverage focused on the AI. The more useful detail for an owner is what it went looking for, because you can check your own computers for the same thing.
See Where Your Business Stands →
A plain-English computer security scan. No card needed to see your results. The scan is on us. If you want step-by-step instructions afterward, that’s a paid report, and you’ll see the price before you decide.
Hey folks! Let me start with what most owners I talk to believe, because it is mostly right. You pay someone to look after your computers. Updates install. Every so often Windows tells you it restarted overnight. That part is handled, and in most of the businesses I see, it really is.
Hold on to that while I walk you through what the researchers found. The details point at a part of the computer that sits just outside that arrangement.
On July 30, 2026, Unit 42, the research team at Palo Alto Networks, published its report. An operator took DeepSeek, a low-cost AI model, and ran it inside Hermes Agent, an open-source program that lets an AI type commands into a computer the way a person would. He sent it instructions through Telegram, the chat app, and checked in when he felt like it.
The AI searched the internet for servers anyone could reach. It pulled public break-in code from GitHub. It chose which flaw to try, ran the attempt, read the result, and decided what to do next. Across the campaign the operator went after more than 460 targets, using a mix of AI-run attempts and his own hands-on work. In one session the researchers rebuilt, from May 7, the only instruction they could recover from the human was the first one.
They also recovered the notes the AI wrote to itself. Looking at a flaw in n8n, a workflow tool, rated 10 out of 10 for severity, it wrote that the flaw “looks extremely promising!”
Then the results, which matter more than the notes. Unit 42 wrote that the AI-run campaigns “did not achieve full compromise of any of their intended targets.” The break-ins that did work, data taken from three Citrix NetScaler systems and commands run on 11 Marimo notebook servers, came from the operator’s own manual work. The researchers’ assessment was measured: autonomous attack cycles “are operationally viable, and the margin of failure was narrow.”
Source: Unit 42, Palo Alto Networks, “AI-Enabled Autonomous Cyberattack Campaign,” July 30, 2026.
I am more interested in the AI’s target list than in the AI itself.
Every target on that list was a program that answered from the open internet and carried a flaw that had already been published. The break-in code came from a public site. For the n8n flaws, the maker had already shipped fixes; Unit 42 lists them as fixed in versions 1.120.4 and 1.121.0. The AI did not discover anything. It read public notes, matched them to servers anyone could find, and tried.
The operator’s manual successes followed the same pattern. NetScaler and Marimo flaws with public identifiers, on systems that were reachable from outside.
So the campaign tells you what gets looked at first: software that has a published flaw and has not had its fix installed. The idea is old. What changed is how little effort it now takes to go down a long list of it, one address after another.
Here is the boundary that matters for your business.
Windows Update never touches third-party software.
It keeps Windows current, and it does that well. It does not update n8n or Langflow. It does not update the PDF reader, the file compression tool, the remote-access program a vendor installed years ago, or the specialty app your office runs on. Each of those has its own updater, or none at all. Some update themselves. Some wait for someone to click. Some have not been touched since the day they were installed.
Nobody has done anything wrong here. That is simply where Windows Update’s job ends, and most service agreements were written around Windows.
So who has been checking the rest?
Most owners I ask have never seen that list for their own machines. That makes sense, because nobody hands it to you. Before you look, try one thing: guess how many programs are installed on the computer you are reading this on. Write the number down.
Then run the Reveal Scan on that Windows computer. It counts the programs it finds and gives you two numbers back: how many are current, and how many need updating. In my experience, most people guess low on the first number. The gap between your guess and the count is the part worth thinking about.
If the second number is bigger than you expected, that is common, and it is work that can be done. You don’t have to be able to do this. We’ll do it with you.
A count is only useful if it leads somewhere, so here is the order I would work in.
Start with anything that answers from the internet. A program that only runs when someone opens it at a desk is a smaller concern than one that sits on a server waiting for connections from outside. The campaign in this story went after the second kind.
Next, look for programs nobody recognizes. Every scan I have looked at turns up a few: a trial someone installed in 2019, a viewer for a file format nobody uses anymore, a tool left behind by a vendor. If nobody needs it, removing it is faster than updating it, and it never needs updating again.
Then work through the rest, the everyday programs that are a version or two behind. Most of those take a few minutes each once someone sits down to do them.
None of this is glamorous. It is a list, worked from the top.
My own father fell for a phishing email. 35+ years in cybersecurity, and it still reached the person I most wanted to look after. Someone got into his computer from far away and went looking for his financial papers. My step-mother noticed something was off and called me, and I stopped them before they reached his bank logins.
That is why I do this the way I do. I have spent 35+ years in cybersecurity. FBI InfraGard trainer. Dozens of managed clients since 1991. None has had ransomware. What that took, year after year, was a person checking the machines on a schedule instead of assuming a tool had it covered.
Fair question, and I would rather you ask it than nod along.
Look at where it fell short. It found targets. It picked real flaws, some rated at the top of the severity scale. It stumbled on the last step, turning a known hole into a working break-in, and it stumbled there on its own while the human operator got through on several. Everything before that last step already runs today, cheaply, on parts anyone can download.
The part I keep coming back to is how the list got built. Each system on it was there because it was reachable from the internet and running software with a published flaw. The machine did not need to be clever to find them. It only had to look.
So the useful question for your business is a narrow one. Is anything on your computers the kind of thing that ends up on a list like that? You can answer it this week, whatever the next version of these tools does.
You already have updates running, and that part is handled. Past the edge of Windows Update there is a second list of programs, and the only way to know its state is to count it. You do not have to do that alone.
When you have your counts, you can book a 15-minute conversation with me or one of our experts about what the scan found. You decide what happens next, and if you never book it, that’s a fine outcome.
You run your business. We keep it running.
Book a 15-Minute Conversation →
Fifteen minutes with a real person about your results. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#AutonomousAI #ThirdPartySoftware #SmallBusinessCybersecurity #Patching #ForwardToSafety
Join the owners who get Craig's Insider Notes every week.
Tagged with: