INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
| 2026-07-31 17:35 CRITICAL HIGH AI-ENABLED ATTACK · AUTONOMOUS VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The threat actor behind the incident attributed to a China-based threat actor operating under aliases "knaithe" and "KnYuan," calls themselves a binary security researcher, has been linked to multiple recent incidents. Their tactics include autonomous AI attacks using compromised Hermes infrastructure, exploiting vulnerabilities in internet-exposed Langflow servers vulnerable to CVE-2026-33017, and leveraging n8n workflow automation platforms. The threat actor also conducts manual attacks against various systems, including Citrix NetScaler, Apache Tomcat, and Windows IKE VPN, targeting vulnerabilities such as CVE-2025-68613 and CVE-2026-21858. Their activities are often facilitated by compromised AI agents that autonomously conduct post-exploitation activity, search for privilege-escalation opportunities, and enumerate services. The threat actor's methods have been reported in multiple incidents, including those attributed to the same group, highlighting their sophistication and adaptability.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation to prevent the use of vulnerable AI models like DeepSeek.
* Regularly update and patch operating systems, software, and applications to ensure they have the latest security patches.
* Use intrusion detection and prevention systems (IDPS) that can detect and block autonomous attacks using AI models.
* Conduct regular security audits and penetration testing to identify vulnerabilities in AI-powered attack tools.
* Educate users about the risks of automating security tasks with AI models, such as DeepSeek, and provide guidance on safe usage practices.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hu•••••.io
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-3055CVE-2026-3055
CVE-2026-34486CVE-2026-34486
CVE-2025-68613CVE-2025-68613
CVE-2026-39987CVE-2026-39987
CVE-2026-33824CVE-2026-33824
CVE-2026-21858CVE-2026-21858
CVE-2026-0300CVE-2026-0300
CVE-2026-33017CVE-2026-33017
Target & Sectors
CN
MY
TH
Incident Timeline
2025/07/31
CrowdStrike reported a significant increase in AI-powered cyber-attacks over the last year.
Click on any entity below to view its context and source!
organisation
Shutterstock.com
Image credits: PJ McDonnell / ImageFlow / Shutterstock.com
Read now: AI-powered Cyber-Attacks Up Significantly in the Last Year, Warns CrowdStrike
May 2026
Hermes was used to conduct a cyberattack against Thailand's Ministry of Finance.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-33017
In a recovered May 2026 session, DeepSeek downloaded a public exploit for
the Langflow code-injection flaw
CVE-2026-33017
, enumerated 84 instances through FOFA, and found one target running version 1.3.4.
The agent first targeted internet-exposed Langflow servers vulnerable to CVE-2026-33017, downloading a public proof-of-concept exploit, identifying 84 exposed instances through FOFA, and scanning them for vulnerable configurations.
general_metric
84 exposed instances
In a recovered May 2026 session, DeepSeek downloaded a public exploit for
the Langflow code-injection flaw
CVE-2026-33017
, enumerated 84 instances through FOFA, and found one target running version 1.3.4.
organisation
FOFA
In a recovered May 2026 session, DeepSeek downloaded a public exploit for
the Langflow code-injection flaw
CVE-2026-33017
, enumerated 84 instances through FOFA, and found one target running version 1.3.4.
infrastructure
1.3.4
In a recovered May 2026 session, DeepSeek downloaded a public exploit for
the Langflow code-injection flaw
CVE-2026-33017
, enumerated 84 instances through FOFA, and found one target running version 1.3.4.
organisation
Autonomous AI
Autonomous AI attack flow
Source: Palo Alto Unit 42
Hermes used in previous cyberattack
The exposed AI campaign comes after another recently disclosed incident in which poorly secured Hermes infrastructure exposed details about an alleged
cyberattack against Thailand's Ministry of Finance
.
organisation
Ministry of Finance
Autonomous AI attack flow
Source: Palo Alto Unit 42
Hermes used in previous cyberattack
The exposed AI campaign comes after another recently disclosed incident in which poorly secured Hermes infrastructure exposed details about an alleged
cyberattack against Thailand's Ministry of Finance
.
organisation
NetScaler
Unit 42 confirmed three successful compromises targeting the Citrix NetScaler vulnerability CVE-2026-3055, which the actor used to extract memory and search for authentication cookies that could be used to hijack sessions.
organisation
CVE-2026
Unit 42 confirmed three successful compromises targeting the Citrix NetScaler vulnerability CVE-2026-3055, which the actor used to extract memory and search for authentication cookies that could be used to hijack sessions.
organisation
Langflow
The agent first targeted internet-exposed Langflow servers vulnerable to CVE-2026-33017, downloading a public proof-of-concept exploit, identifying 84 exposed instances through FOFA, and scanning them for vulnerable configurations.
infrastructure
N8N
DeepSeek then analyzed multiple public exploit repositories before selecting the n8n workflow automation platform to target, which had more than 647,000 exposed instances identified through FOFA.
organisation
CVE-2025-68613
The agent downloaded an exploit that chained CVE-2026-21858 and CVE-2025-68613, identified servers running vulnerable versions, and checked them for unauthenticated file-upload forms required to complete the attack.
infrastructure
Windows
While the AI agent was used extensively, the threat actor also conducted manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.
organisation
Citrix NetScaler
While the AI agent was used extensively, the threat actor also conducted manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.
organisation
GLM
The actor had also configured other AI coding platforms, including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI's Codex, but Unit 42 found that they were not used often.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
2026/07/24
Hunt.io and security researcher Bob Diachenko discovered open web directories containing exploit tools, web shells, credentials, compiled payloads, and Hermes activity logs on vulnerable servers.
Click on any entity below to view its context and source!
organisation
BleepingComputer
Last week, BleepingComputer reported that Hunt.io and security researcher Bob Diachenko discovered open web directories containing exploit tools, web shells, credentials, compiled payloads, and Hermes activity logs.
July 30
Palo Alto Networks provided threat intelligence to Unit 42.
Click on any entity below to view its context and source!
attribution
Palo Alto Networks
These AI-augmented offensive capabilities “enabled them to dramatically increase the speed and scale of their campaigns,” said Andy Piazza, senior director of threat intelligence within Unit 42, Palo Alto Networks’ research team, in
a report
published on July 30.
Jul 31, 2026
Threat actors used DeepSeek AI to autonomously attack vulnerable servers.
2026/07/31
A Chinese-speaking threat actor used DeepSeek AI to orchestrate vulnerability exploits against vulnerable servers.
Click on any entity below to view its context and source!
infrastructure
N8N
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
FOFA returned 25,209 n8n systems in China during the session.
They span eight Common Vulnerabilities and Exposures (CVE) identifiers because the n8n chain combines two vulnerabilities.
The DeepSeek-led attacks against Langflow and n8n failed because the exposed systems did not meet the exploits' configuration requirements.
Organizations should patch exposed Langflow, n8n and Marimo systems, along with customer-managed NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers.
The agent then surveyed 10 product families, searched GitHub for recent proof-of-concept repositories and selected n8n, the workflow automation platform.
More than 50 additional targets also lacked a usable public form, so no n8n system was compromised.
n8n fixed
CVE-2026-21858 in version 1.121.0
.
organisation
CVE-2026-21858
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
CVE-2025-68613
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
It fixed
CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0
.
infrastructure
Windows
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
GLM
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
CVE-2026-34486
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
CVE-2026-39987
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
CVE-2026-0300
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
CVE-2026-33824
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
NetScaler ADC & Gateway
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
PAN
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
User-ID Authentication Portal
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
Windows IKE Extensions
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
Evidence of Trial and Testing of AI Tools
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
OpenAI’s
This research led the agent to pivot to seven higher-value vulnerabilities:
CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2026-3055 (CVSS rating: 9.8): Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Trial and Testing of AI Tools
In parallel with their use of
DeepSeek
as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.
organisation
CVE-2026-33017
Langflow fixed CVE-2026-33017 in version 1.9.0.
infrastructure
1.9.0
Langflow fixed CVE-2026-33017 in version 1.9.0.
organisation
NetScaler ADC
Organizations should patch exposed Langflow, n8n and Marimo systems, along with customer-managed NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers.
organisation
GitHub
The agent then surveyed 10 product families, searched GitHub for recent proof-of-concept repositories and selected n8n, the workflow automation platform.
victims
50 additional targets
More than 50 additional targets also lacked a usable public form, so no n8n system was compromised.
infrastructure
1.121.0
n8n fixed
CVE-2026-21858 in version 1.121.0
.
organisation
CVE-2025
It obtained a chain combining the unauthenticated file-access flaw
CVE-2026-21858
with the expression-injection issue
CVE-2025-68613
.
infrastructure
1.120.4
It fixed
CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0
.
infrastructure
1.121.1
It fixed
CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0
.
Version 1.121.1 is therefore the earliest release that addresses both flaws used in the attempted chain.
infrastructure
1.122.0
It fixed
CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0
.
organisation
NetScaler
In separate manual operations, Unit 42 reported data exfiltration from three organizations through the
NetScaler memory-overread flaw CVE-2026-3055
and command execution on 11 Marimo instances through
CVE-2026-39987
.
organisation
CVE-2026
In separate manual operations, Unit 42 reported data exfiltration from three organizations through the
NetScaler memory-overread flaw CVE-2026-3055
and command execution on 11 Marimo instances through
CVE-2026-39987
.
organisation
Hacker
Hacker uses DeepSeek AI to autonomously attack vulnerable servers.
organisation
Palo Alto Networks'
The activity was discovered by Palo Alto Networks' Unit 42 researchers after Hermes accidentally created a web server from its home directory, exposing the attacker's environment, including API keys, exploit scripts, target lists, shell history, and AI attack logs.
organisation
API
The activity was discovered by Palo Alto Networks' Unit 42 researchers after Hermes accidentally created a web server from its home directory, exposing the attacker's environment, including API keys, exploit scripts, target lists, shell history, and AI attack logs.
The unintended HTTP server made the actor's model configurations, application programming interface (API) keys, exploit scripts, target lists, shell history, and autonomous-session logs accessible, according to the
company's report
.
organisation
Telegram
Hermes was configured to accept instructions from a Telegram channel, use custom offensive-security skills, and integrate with the FOFA internet asset search engine.
After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits.
organisation
FOFA
Hermes was configured to accept instructions from a Telegram channel, use custom offensive-security skills, and integrate with the FOFA internet asset search engine.
organisation
AI Orchestration
AI Orchestration and Manual Vulnerability Exploitation
The threat actor is a Chinese-speaking individual operating under the aliases ‘knaithe’ and ‘KnYuan’ and based in Zhuhai, China.
infrastructure
0.23.0
Marimo fixed
CVE-2026-39987 in version 0.23.0
.
organisation
Chinese Hacker Uses
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits.
organisation
Orchestrate Vulnerability
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits.
organisation
PoC
It initially surveyed 10 product families, scanning GitHub for trending proofs of concept (PoC) exploits and prioritizing vulnerabilities by attack surface.
organisation
The Hacker News
The Hacker News has contacted Palo Alto Networks for clarification and will update the story with any response.
victims
460 targets
The operator, tracked through the aliases
knaithe
and
KnYuan
, launched exploitation attempts against more than 460 targets using autonomous and conventional workflows.
infrastructure
8888 http.server
Hermes Agent exposed the operation by starting python3 -m http.server 8888 from /home/worker.
Tactical Metrics
Metrics
infrastructure
N8N
Affected Product
Click for context!
DeepSeek then analyzed multiple public exploit repositories before selecting the n8n workflow automation platform to target, which had more than 647,000 exposed instances identified through FOFA.
…vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
CVE-2025-68613 (CVS…
FOFA returned 25,209 n8n systems in China during the session.
They span eight Common Vulnerabilities and Exposures (CVE) identifiers because the n8n chain combines two vulnerabilities.
The DeepSeek-led attacks against Langflow and n8n failed because the exposed systems did not meet the exploits' configuration requirements.
Organizations should patch exposed Langflow, n8n and Marimo systems, along with customer-managed NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers.
The agent then surveyed 10 product families, searched GitHub for recent proof-of-concept repositories and selected n8n, the workflow automation platform.
More than 50 additional targets also lacked a usable public form, so no n8n system was compromised.
n8n fixed
CVE-2026-21858 in version 1.121.0
.
Metrics
infrastructure
Windows
Affected Product
While the AI agent was used extensively, the threat actor also conducted manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.
…Portal vulnerability with manual non-functional research PoC cloned (not executed)
CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)
Evidence of Tr…
Metrics
infrastructure
1.3.4
Software Version
In a recovered May 2026 session, DeepSeek downloaded a public exploit for
the Langflow code-injection flaw
CVE-2026-33017
, enumerated 84 instances through FOFA, and found one target running version 1.3.4.
Metrics
victims
50
Additional Targets
More than 50 additional targets also lacked a usable public form, so no n8n system was compromised.
Metrics
infrastructure
1.9.0
Software Version
Langflow fixed CVE-2026-33017 in version 1.9.0.
Metrics
infrastructure
1.121.0
Software Version
n8n fixed
CVE-2026-21858 in version 1.121.0
.
Metrics
infrastructure
1.120.4
Software Version
It fixed
CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0
.
Metrics
infrastructure
1.121.1
Software Version
It fixed
CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0
.
Version 1.121.1 is therefore the earliest release that addresses both flaws used in the attempted chain.
Metrics
infrastructure
1.122.0
Software Version
It fixed
CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0
.
Metrics
infrastructure
0.23.0
Software Version
Marimo fixed
CVE-2026-39987 in version 0.23.0
.
Metrics
victims
460
Targets
The operator, tracked through the aliases
knaithe
and
KnYuan
, launched exploitation attempts against more than 460 targets using autonomous and conventional workflows.
Metrics
infrastructure
8,888
Http.Server
Hermes Agent exposed the operation by starting python3 -m http.server 8888 from /home/worker.
Intelligence Sources
Infosecurity-Magazine
2026-07-31
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
Infosecurity-Magazine
BleepingComputer
2026-07-31
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
BleepingComputer
The Hacker News
2026-07-31
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-03T10:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
36x
organisation
Identified Entity
Autonomous AI
entity
9x
timeline
Temporal Reference
2026/07/24
date
8x
vulnerability
Exploited CVE
CVE-2026-33017
cve
7x
infrastructure
Software Version
1.3.4
version
3x
target region
Target Country
China
country
3x
tactic
MITRE ATT&CK Technique
T1588.005 - Exploits
technique
2x
industry
Targeted Sector
Finance
sector
2x
general metric
Exposed Instances
84
exposed instances
2x
infrastructure
Affected Product
N8N
software
2x
general metric
%
54
%
2x
attribution
Attributing Entity
Palo Alto Networks
authority
2x
general metric
Deepseek
100
deepseek
Contextual Telemetry
Context Block
12 METRICS
general metric
Hermes
42
hermes
general metric
Systems
460
systems
source region
Origin Country
China
country
general metric
Automation Vulnerability
8
automation vulnerability
general metric
Product Families
10
product families
general metric
N8N Systems
25,209
n8n systems
tactic
Cyber Operation Type
Exfiltration
tactic
general metric
Marimo Instances
11
marimo instances
victims
Additional Targets
50
additional targets
general metric
Khandelwal Jul
31
khandelwal jul
victims
Targets
460
targets
infrastructure
Http.Server
8,888
http.server
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.