ZeroHour
Victim

French telecom subscribers

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Hackers Turn AI Agent Into a Cyber Weapon After Deleting Its Safety Refusals

Researchers exposed BlackHatSect0r && DXQRTXX infrastructure showing a safety-disabled Hermes AI agent used to automate scanning, credential harvesting, and vishing against French telecom subscribers.

Socradar-analyzed infrastructure attributed to French-speaking crew BlackHatSect0r && DXQRTXX exposed 4.9 GB across 9,299 files, including the DXSCAN Go-based C2 platform, 16,834 harvested credentials, and a database of nearly 450,000 records used for a vishing campaign targeting older French telecom subscribers with Societe Generale-themed lures. The crew ran a self-hosted Nous Research Hermes agent on a DeepSeek model with refusal instructions removed and HERMES_DISABLE_SAFETY=1 set, using it for scanning, secret hunting, and Telegram reporting. DXSCAN queued 2.75 million domains and reached over 726,000 hosts; the toolkit relied on exposed secrets and misconfigurations rather than novel exploitation.

GBHackersupdated · 4h agofirst · 7h agoThreat actor in the wild 4 sourcesCVE-2026-425301

Related CVEs

  • NGINX Open Source has a vulnerability in the ngx_http_v3_module module.
    NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS)…
    · f5 nginx gateway fabric · f5 nginx ingress controller

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.