


Perceptive Security
SOC/SIEM Consultancy

Hacker uses DeepSeek AI to autonomously attack vulnerable servers
Published:
31 July 2026 at 19:35:35
Alert date:
31 July 2026 at 20:01:57
Source:
bleepingcomputer.com
Emerging Technologies, Web Technologies, Enterprise Applications, Zero-Day Vulnerabilities, Network Infrastructure
A Chinese-speaking threat actor is leveraging the DeepSeek AI model combined with the open-source Hermes Agent to conduct autonomous cyberattacks against exposed servers. The attacks require minimal human involvement, representing a new frontier in AI-assisted offensive security operations. The use of DeepSeek, a powerful open-source Chinese AI model, lowers the barrier for automated exploitation of vulnerable infrastructure. The Hermes Agent acts as an orchestration layer, enabling the AI to autonomously identify and attack targets. This incident highlights the growing risk of AI models being weaponized for offensive cyber operations with reduced human oversight.
Technical details
A Chinese-speaking threat actor using aliases 'knaithe' and 'KnYuan' employed the DeepSeek AI model as a reasoning engine within the open-source Hermes Agent framework to conduct autonomous cyberattacks against exposed servers with minimal human involvement. The attack was discovered by Palo Alto Networks Unit 42 after Hermes accidentally created a web server from its home directory, exposing the attacker's environment including API keys, exploit scripts, target lists, shell history, and AI attack logs. Hermes Agent supports a 'Yolo' mode allowing it to execute commands, including risky ones, without operator approval. The agent was configured to receive instructions via a Telegram channel, use custom offensive-security skills, and integrate with the FOFA internet asset search engine. In a recovered May 2026 session, the operator provided only an initial task and the agent operated autonomously thereafter. The agent first targeted internet-exposed Langflow servers vulnerable to CVE-2026-33017, downloading a public PoC exploit, identifying 84 exposed instances via FOFA, and scanning for vulnerable configurations. After determining those targets were unexploitable, it pivoted to n8n workflow automation platform, identifying over 647,000 exposed instances via FOFA and downloading an exploit chaining CVE-2026-21858 and CVE-2025-68613. Autonomous exploitation attempts failed as discovered upload forms required authentication. Additionally, the threat actor conducted manual attacks against 460+ systems targeting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and others. Three successful compromises were confirmed via CVE-2026-3055 in Citrix NetScaler, used to extract memory and search for authentication cookies. The actor also configured but rarely used Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI Codex platforms.
Mitigation steps:
1. Patch immediately: Apply available patches for CVE-2026-33017 (Langflow), CVE-2026-21858 and CVE-2025-68613 (n8n), and CVE-2026-3055 (Citrix NetScaler). 2. Reduce internet exposure: Audit and restrict internet-exposed instances of Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, and Windows IKE VPN. 3. Monitor for authentication anomalies: Watch for session hijacking attempts, unusual authentication cookie usage, and unauthorized memory extraction on NetScaler devices. 4. Scan for unauthenticated file upload endpoints and ensure all file upload forms require authentication. 5. Use FOFA or similar tools proactively to identify your own internet-exposed assets before attackers do. 6. Monitor for Hermes Agent activity indicators including unexpected web servers, exposed directories, and YOLO-mode autonomous command execution. 7. Implement network monitoring for unusual Telegram-based C2 communications. 8. Secure API keys and sensitive credentials to prevent exposure via misconfigured services. 9. Deploy breach and attack simulation tools to validate SIEM and EDR detection coverage. 10. Restrict or monitor use of AI coding and agent platforms (DeepSeek, Qwen, GLM, Kimi, MiniMax, Claude Code, OpenAI Codex) within your environment for potential misuse.
Affected products:
Langflow (vulnerable to CVE-2026-33017)
n8n workflow automation platform (vulnerable to CVE-2026-21858 and CVE-2025-68613)
Citrix NetScaler (vulnerable to CVE-2026-3055)
Apache Tomcat
Marimo Notebook
Windows IKE VPN
Related links:
https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/
https://www.bleepingcomputer.com/news/security/openai-agent-used-exposed-credentials-at-4-services-in-hugging-face-breach/
https://www.bleepingcomputer.com/news/security/your-ai-agents-are-guessing-at-scale-permissions-decide-the-damage/
https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-days-to-escape-to-the-internet/
Related CVE's:
Related threat actors:
IOC's:
Telegram channel used as command-and-control interface for Hermes Agent, FOFA search engine queries for Langflow and n8n exposed instances, Aliases: knaithe, KnYuan, Hermes Agent open-source framework with YOLO mode enabled, DeepSeek AI model used as reasoning engine, Exposed web server created accidentally by Hermes from attacker's home directory containing API keys, exploit scripts, and target lists
This article was created with the assistance of AI technology by Perceptive.
