Exploited in the wild Langflow knaithe ai-ml n8n DeepSeek
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
CVE Tools coverage
A Chinese-speaking threat actor leveraged the DeepSeek AI model through the Hermes Agent framework to execute autonomous cyberattacks. Using Telegram for initial instructions, the agent identified vulnerable internet-facing systems and deployed public exploits without further human input. The operation targeted over 460 systems across several high-risk vulnerabilities, including CVE-2026-3055 (NetScaler) and CVE-2026-39987 (Marimo), though only three successful breaches were confirmed. Organizations are urged to apply patches for exposed Langflow, n8n, and Marimo systems, as well as secure customer-managed NetScaler appliances.