CVE Tools
Back to feed
Exploited in the wild Langflow knaithe ai-ml n8n DeepSeek

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

BleepingComputer·By Lawrence Abrams··3 min read
CVE Tools coverage

A Chinese-speaking threat actor has deployed the DeepSeek AI model alongside the Hermes Agent to carry out autonomous cyberattacks against internet-exposed servers with minimal human oversight. Researchers from Palo Alto Networks' Unit 42 uncovered this activity when Hermes inadvertently exposed internal data, including API keys, exploit scripts, and logs of AI-driven attacks.

The campaign highlights a new offensive workflow where an AI agent can identify, evaluate, and attempt to compromise vulnerable systems independently. While no successful breaches were recorded during the observed automated efforts, the speed and autonomy of the operation are alarming. The agent targeted vulnerabilities like CVE-2026-33017 and CVE-2026-21858 across products such as Langflow, n8n, and Citrix NetScaler, though these attempts ultimately failed due to authentication barriers.

In parallel, the actor manually exploited over 460 systems using flaws in various technologies. This marks one of the first known cases of an AI tool conducting large-scale reconnaissance and attack planning without constant human input.