Decision RecordActivePublished without chair review
CRT-2026-015501 Aug 2026MORNING EDITIONDaily Roundtable
Controls for AI-assisted exploitation and agent runtimes
Treat exposed application servers matching reported AI-assisted activity as compromise candidates, and restrict internal AI-agent runtime egress, credentials, tool permissions, production access, approval paths, and logging.
Current public guidance · the full record
What to do now
Under reviewAt a glanceWithin 24 to 72 hours, inventory exposed Tomcat, NetScaler, Langflow, and Marimo systems and treat any that match the reported DeepSeek/Hermes activity as compromise candidates.
For those matching systems, isolate as needed, review for compromise, and preserve logs for investigation. For internal AI-agent runtimes, move to deny-by-default egress, scoped credentials, separated tool permissions, restricted production access, human approval for sensitive actions, and logging.
Do not base response decisions on claims of a named threat group or fully autonomous AI behavior; the supported action is exposure hunting and delegated-authority control tightening.
Why now
Under reviewThe packet describes the issue as active and operationally urgent because DeepSeek/Hermes was reported in an AI-assisted intrusion workflow against exposed servers, including about 460 targets, three confirmed compromises, and command execution on Marimo instances.
The final synthesis treats the broader signal as rapid abuse of high-authority exposed systems and says the DeepSeek/Hermes case should be handled as attacker-workflow acceleration.
That timing supports immediate hunting of matching exposed Tomcat, NetScaler, Langflow, and Marimo systems and immediate restriction of AI-agent runtime authority, rather than waiting for stronger attribution.
Who is affected
Under reviewOperators of internet-exposed Tomcat, NetScaler, Langflow, and Marimo systems are affected when those systems match the reported DeepSeek/Hermes activity; their exposure is potential compromise following AI-assisted reconnaissance, exploit selection, and orchestration.
Operators of Marimo instances have a distinct concern because the packet describes command execution on Marimo instances.
Security teams responsible for AI-agent runtimes are affected when agents have external network egress, credentials, delegated tools, production access, approval authority, or incomplete logging; the consequence is over-broad delegated authority being used or abused at machine speed.
Executives and incident leads are affected by the attribution boundary: response should not depend on naming a group or claiming autonomous AI when the packet supports a narrower Chinese-speaking operator and AI-assisted workflow framing.
What supports this
Under reviewThe final synthesis supports immediate action by treating DeepSeek/Hermes as acceleration of attacker workflow, not AI going rogue, and by emphasizing rapid abuse of high-authority exposed systems.
The intelligence analysis supports the intrusion-workflow characterization: Hermes Agent/DeepSeek was described as used for FOFA-style reconnaissance, exploit selection, orchestration against about 460 targets, three confirmed compromises, and command execution on Marimo instances; it also limits attribution confidence.
The AI-security analysis supports runtime controls by framing the issue as delegated authority with a faster, less predictable decision layer, not a wholly new AI-autonomy class.
The narrowing analysis supports keeping the action bounded: DeepSeek/Hermes against exposed servers is one operational signal, not proof of one unified campaign or root cause across unrelated incidents.
The evidence review supports the recommended controls: sandboxing, deny-by-default egress, scoped credentials, separated tool permissions, human approval for sensitive actions, and logging.
How the Roundtable reached this
Under reviewThe Roundtable separated the operational signal from the label.
The intelligence analysis described DeepSeek/Hermes activity as an AI-assisted intrusion workflow: FOFA-style reconnaissance, exploit selection, orchestration against about 460 targets, three confirmed compromises, and command execution on Marimo instances, while limiting attribution beyond a Chinese-speaking operator.
The AI-security analysis pushed back on treating this as a wholly new autonomous-AI threat class and reframed it as delegated authority with a faster decision layer.
The final synthesis and decision review resolved the issue as an operational-control decision: hunt exposed Tomcat, NetScaler, Langflow, and Marimo systems that match the reported activity, and harden internal AI-agent runtimes without overstating actor attribution or AI autonomy.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 12 candidate signals.
- Linker (AI panel role)Linker evaluated 12 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 26 evidence signals; 14 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 2 predictions and rejected 4 claims.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 16 public/private findings.
- Arbiter (AI panel role)Arbiter produced 12 decision envelopes.
Key disagreement
Scout (AI panel role)
The packet warns not to overstate state attribution or describe the activity as AI going rogue. Confidence is stronger on the AI-assisted workflow than on actor identity.
Arbiter outcome
Arbiter outcome: new decision record. A new operational Decision Record is supported. The core action is clear, and the remaining issue is to keep technology lists and AI-assisted framing tied to the reported activity rather than overstating attribution or autonomy.
Candidates considered
Considered 12 candidates · opened 1 · 11 not opened (11 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingActor identity is uncertain beyond the reported Chinese-speaking operator framing; the packet says there is not enough support for a named group, state nexus, or infrastructure lineage.
The degree of AI autonomy is also uncertain: the discussion supports AI-assisted reconnaissance, exploit selection, orchestration, and command execution, but warns against describing the activity as AI acting on its own.
The exact completeness of the Tomcat, NetScaler, Langflow, and Marimo target list is uncertain because the primary report and raw telemetry are not in the packet.
What evidence is missing
MissingThe packet does not include the primary public report or underlying telemetry for the full named technology list and observed compromise details.
That means the Tomcat, NetScaler, Langflow, and Marimo targeting list should be treated as based on the briefing and Roundtable discussion, not independently verified inside this packet.
The packet also does not include logs, indicators, exploit traces, or victim-side evidence that would let operators confirm whether the three reported compromises and Marimo command execution generalize beyond the cited activity.
What would change this
Under reviewThis decision would narrow if later evidence shows the DeepSeek/Hermes activity was only scanning, did not compromise exposed systems, or did not involve Tomcat, NetScaler, Langflow, and Marimo as described in the briefing.
It would also change if primary telemetry shows a different technology list, different intrusion path, or no command execution on Marimo instances.
The AI-agent runtime controls would remain relevant unless evidence shows the activity did not use delegated tools, credentials, orchestration, or agent-like execution paths.
What to watch next
Under reviewWatch for the primary public report, indicators, or telemetry that confirm or narrow the Tomcat, NetScaler, Langflow, and Marimo exposure list.
If the activity proves to be scanning only, reduce the response from compromise review to exposure reduction and monitoring. If matching assets are high-authority systems or show command execution, escalate to containment, credential review, and forensic investigation.
For AI-agent runtimes, watch for agents with broad egress, reusable credentials, tool permissions that cross duties, production write access, or missing logs; when found, restrict those permissions before expanding agent use.
Evidence basis
Summary: Today’s strongest decision signal is not one single campaign; it is rapid abuse of high-authority exposed systems. Per the briefing/CISA KEV, Cisco Secure FMC CVE-2026-20316 and Adobe ColdFusion CVE-2026-48282 need same-day contain…
Public value history
- 01 Aug 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 01 Aug 2026Methodology
How the panel reaches a Public Decision Record.