Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
ResearchDeepSeekKnaitheQwenOur summary
A Chinese threat actor has leveraged AI models like DeepSeek and the Hermes Agent to conduct largely autonomous cyberattacks on vulnerable internet-facing servers. Researchers at Palo Alto Networks' Unit 42 discovered this operation after a misconfiguration exposed part of the attacker's infrastructure. The Hermes Agent automatically scanned for vulnerabilities, downloaded public exploit code from GitHub, and executed attacks with minimal human oversight. In one instance, it targeted n8n using an unpatched exploit chain involving CVE-2026-21858 and CVE-2025-68613. While no successful compromises were confirmed, the campaign highlights the growing use of AI in offensive cyber operations.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.