Китайский хакер использовал DeepSeek для проведения автономных атак
Researchers at Palo Alto Networks discovered a Chinese-speaking hacker using the DeepSeek AI model and open-source framework Hermes Agent to conduct autonomous cyberattacks on internet-exposed servers. After receiving initial instructions via Telegram, the AI agent independently searched for targets, identified vulnerabilities, downloaded exploits, and attempted attacks without further human input.
The campaign was uncovered due to an error in Hermes, which accidentally exposed the attacker's working environment through an HTTP server command. Researchers obtained API keys, configuration files, exploit code, target lists, and session logs from the incident. The attackers are believed to operate under the aliases knaithe and KnYuan, possibly based in Zhuhai, China.
During one attack sequence in May 2026, the AI agent targeted vulnerable Langflow instances affected by CVE-2026-33017 but failed to fully exploit them. It later shifted focus to automation platforms like n8n, combining CVE-2026-21858">CVE-2026-21858 and CVE-2025-68613">CVE-2025-68613. While no confirmed breaches occurred, researchers emphasized the efficiency of the AI agent in filtering targets and reducing hundreds of hours of manual labor into minutes.