CVE Tools

Китайский хакер использовал DeepSeek для проведения автономных атак

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedLangflowknaithen8n

Our summary

Researchers at Palo Alto Networks discovered a Chinese-speaking hacker using the DeepSeek AI model and open-source framework Hermes Agent to conduct autonomous cyberattacks on internet-exposed servers. After receiving initial instructions via Telegram, the AI agent independently searched for targets, identified vulnerabilities, downloaded exploits, and attempted attacks without further human input.
The campaign was uncovered due to an error in Hermes, which accidentally exposed the attacker's working environment through an HTTP server command. Researchers obtained API keys, configuration files, exploit code, target lists, and session logs from the incident. The attackers are believed to operate under the aliases knaithe and KnYuan, possibly based in Zhuhai, China.
During one attack sequence in May 2026, the AI agent targeted vulnerable Langflow instances affected by CVE-2026-33017 but failed to fully exploit them. It later shifted focus to automation platforms like n8n, combining CVE-2026-21858">CVE-2026-21858 and CVE-2025-68613">CVE-2025-68613. While no confirmed breaches occurred, researchers emphasized the efficiency of the AI agent in filtering targets and reducing hundreds of hours of manual labor into minutes.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store