Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Reported exploitedLangflowknaithen8nOur summary
A Chinese-speaking threat actor leveraged the DeepSeek AI model through the Hermes Agent framework to execute autonomous cyberattacks. Using Telegram for initial instructions, the agent identified vulnerable internet-facing systems and deployed public exploits without further human input. The operation targeted over 460 systems across several high-risk vulnerabilities, including CVE-2026-3055 (NetScaler) and CVE-2026-39987 (Marimo), though only three successful breaches were confirmed. Organizations are urged to apply patches for exposed Langflow, n8n, and Marimo systems, as well as secure customer-managed NetScaler appliances.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.