Researchers identified a Chinese-speaking threat actor running what is described as one of the first large-scale autonomous AI hacking operations: an open-source attack framework wired to a DeepSeek language model and pointed at more than 460 targets across 47 countries with minimal human input. Alongside a related campaign exploiting VMware vCenter flaws for root-level remote code execution, the operation compromised at least 361 victim organizations, concentrated in Germany, the United States, Turkey, Iran, and France, deploying Babuk-derived ransomware. The activity was first detected around August 3, 2026 and peaked days later.