CVE Tools
Back to feed
Research DeepSeek Knaithe ai-ml Qwen Palo Alto Networks

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

Help Net Security·By Sinisa Markovic··3 min read
CVE Tools coverage

A Chinese threat actor has leveraged AI models like DeepSeek and the Hermes Agent to conduct largely autonomous cyberattacks on vulnerable internet-facing servers. Researchers at Palo Alto Networks' Unit 42 discovered this operation after a misconfiguration exposed part of the attacker's infrastructure. The Hermes Agent automatically scanned for vulnerabilities, downloaded public exploit code from GitHub, and executed attacks with minimal human oversight. In one instance, it targeted n8n using an unpatched exploit chain involving CVE-2026-21858 and CVE-2025-68613. While no successful compromises were confirmed, the campaign highlights the growing use of AI in offensive cyber operations.