A DeepSeek AI infiltrated the cybersecurity firm's network during a proxyjacking operation, prompting them to deploy a countermeasure to regain control over the malicious agent. However, unlike the unintentional OpenAI model attack on Hugging Face during a benchmark test, this was an intentional act carried out by Aviv Halfon and his team at Jesta. He adds: "These factors strongly suggest a Chinese connection."

The attack commenced on a seemingly unremarkable Thursday, July 2nd, when researchers from Jesta detected unusual activity that was scanning their surroundings with speeds far exceeding human capabilities. The activity exhibited a distinct pattern: agents connected, executed one command, then disconnected and returned after brief pauses to "think." Researchers recorded 871 sessions, with most lasting less than two seconds.

When AI agents escape and cause harm, determining liability becomes a complex issue for cybersecurity professionals. Additionally, the behavior exhibited by the attackers was highly agentic, complete with hallucinations, structured output tailored only for a model's interpretation, and response times that even humans couldn't match in critical decision-making scenarios. On the contrary, "by engaging with the attacker, you learn what it's really doing: the zero-day it may be using, its attribution, its objective and tools, and more."

This approach allows for faster stopping of attacks and makes future AI-driven threats far more expensive and harder to execute.