INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

| 2026-07-31 17:35 CRITICAL HIGH AI-ENABLED ATTACK · AUTONOMOUS VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The threat actor behind the incident attributed to a China-based threat actor operating under aliases "knaithe" and "KnYuan," calls themselves a binary security researcher, has been linked to multiple recent incidents. Their tactics include autonomous AI attacks using compromised Hermes infrastructure, exploiting vulnerabilities in internet-exposed Langflow servers vulnerable to CVE-2026-33017, and leveraging n8n workflow automation platforms. The threat actor also conducts manual attacks against various systems, including Citrix NetScaler, Apache Tomcat, and Windows IKE VPN, targeting vulnerabilities such as CVE-2025-68613 and CVE-2026-21858. Their activities are often facilitated by compromised AI agents that autonomously conduct post-exploitation activity, search for privilege-escalation opportunities, and enumerate services. The threat actor's methods have been reported in multiple incidents, including those attributed to the same group, highlighting their sophistication and adaptability.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation to prevent the use of vulnerable AI models like DeepSeek. * Regularly update and patch operating systems, software, and applications to ensure they have the latest security patches. * Use intrusion detection and prevention systems (IDPS) that can detect and block autonomous attacks using AI models. * Conduct regular security audits and penetration testing to identify vulnerabilities in AI-powered attack tools. * Educate users about the risks of automating security tasks with AI models, such as DeepSeek, and provide guidance on safe usage practices.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hu•••••.io
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-3055CVE-2026-3055 CVE-2026-34486CVE-2026-34486 CVE-2025-68613CVE-2025-68613 CVE-2026-39987CVE-2026-39987 CVE-2026-33824CVE-2026-33824 CVE-2026-21858CVE-2026-21858 CVE-2026-0300CVE-2026-0300 CVE-2026-33017CVE-2026-33017
Target & Sectors
CN MY TH
Incident Timeline
‎2025/07/31
CrowdStrike reported a significant increase in AI-powered cyber-attacks over the last year.
organisation Shutterstock.com
‎May 2026
Hermes was used to conduct a cyberattack against Thailand's Ministry of Finance.
vulnerability CVE-2026-33017
general_metric 84 exposed instances
organisation FOFA
infrastructure 1.3.4
organisation Autonomous AI
organisation Ministry of Finance
organisation NetScaler
organisation CVE-2026
organisation Langflow
infrastructure N8N
organisation CVE-2025-68613
infrastructure Windows
organisation Citrix NetScaler
organisation GLM
organisation EDR
‎2026/07/24
Hunt.io and security researcher Bob Diachenko discovered open web directories containing exploit tools, web shells, credentials, compiled payloads, and Hermes activity logs on vulnerable servers.
organisation BleepingComputer
‎July 30
Palo Alto Networks provided threat intelligence to Unit 42.
attribution Palo Alto Networks
‎Jul 31, 2026
Threat actors used DeepSeek AI to autonomously attack vulnerable servers.
‎2026/07/31
A Chinese-speaking threat actor used DeepSeek AI to orchestrate vulnerability exploits against vulnerable servers.
infrastructure N8N
organisation CVE-2026-21858
organisation CVE-2025-68613
infrastructure Windows
organisation GLM
organisation CVE-2026-34486
organisation CVE-2026-39987
organisation CVE-2026-0300
organisation CVE-2026-33824
organisation NetScaler ADC & Gateway
organisation PAN
organisation User-ID Authentication Portal
organisation Windows IKE Extensions
organisation Evidence of Trial and Testing of AI Tools
organisation OpenAI’s
organisation CVE-2026-33017
infrastructure 1.9.0
organisation NetScaler ADC
organisation GitHub
victims 50 additional targets
infrastructure 1.121.0
organisation CVE-2025
infrastructure 1.120.4
infrastructure 1.121.1
infrastructure 1.122.0
organisation NetScaler
organisation CVE-2026
organisation Hacker
organisation Palo Alto Networks'
organisation API
organisation Telegram
organisation FOFA
organisation AI Orchestration
infrastructure 0.23.0
organisation Chinese Hacker Uses
organisation Orchestrate Vulnerability
organisation PoC
organisation The Hacker News
victims 460 targets
infrastructure 8888 http.server
Tactical Metrics
Metrics
infrastructure
‎N8N
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎1.3.4
Software Version
Metrics
victims
50
Additional Targets
Metrics
infrastructure
‎1.9.0
Software Version
Metrics
infrastructure
‎1.121.0
Software Version
Metrics
infrastructure
‎1.120.4
Software Version
Metrics
infrastructure
‎1.121.1
Software Version
Metrics
infrastructure
‎1.122.0
Software Version
Metrics
infrastructure
‎0.23.0
Software Version
Metrics
victims
460
Targets
Metrics
infrastructure
8,888
Http.Server
Intelligence Sources