- Jesta Security detected the first live LLM-managed cyber attack campaign, lasting five days and using 871 sessions.
- The exact model behind the attack was identified as deepseek-v4-flash-free (DeepSeek V4 Flash free tier) from inside the intrusion.
- Researchers took control of the AI agent, extracting its target list and operational details.
- The goal was proxyjacking: installing SOCKS5 proxies to create a network of base stations for further attacks.