Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Ai-Powered Cyberattack: DeepSeek Autonomous Hacking Platform Uncovered


A recent report has uncovered a sophisticated AI-powered hacking campaign that utilizes an autonomous platform called DeepSeek to conduct cyberattacks. The platform, which is capable of autonomously scanning targets and launching attacks without human intervention, was found to be used in multiple high-profile attacks in June.

  • The researchers at Unit 42 discovered a sophisticated AI-powered hacking campaign using the DeepSeek autonomous platform.
  • The platform can autonomously scan targets, select exploits, and launch attacks without human intervention.
  • The campaign used other AI-powered tools, including Qwen, GLM, Kimi, and MiniMax.
  • The actor behind the campaign trusted Western tools less than DeepSeek, which connected directly to its native APIs.
  • The campaign highlights the importance of building systems with default settings that are tighter than average.



  • A recent report by Unit 42 has shed light on a sophisticated AI-powered hacking campaign that utilizes an autonomous platform called DeepSeek to conduct cyberattacks. The platform, which is built using the Hermes Agent framework, was discovered to be capable of autonomously scanning targets, selecting exploits, and launching attacks without human intervention.

    The researchers behind the report, Unit 42, uncovered this autonomous hacking platform while tracking a Chinese-speaking actor who was responsible for multiple high-profile attacks in June. The actor had customized the Hermes Agent framework with various skills, including custom procedures for internet asset enumeration, LLM jailbreaking, and WebSocket exploitation.

    DeepSeek, the autonomous platform at the heart of the campaign, was found to be capable of executing hundreds of hours of manual targeting analysis in mere minutes. This level of speed and efficiency is a significant departure from traditional human-driven hacking campaigns, which often require significantly more time and resources to achieve similar results.

    The DeepSeek platform was used to scan for 84 live instances of the Langflow vulnerability (CVE-2026-33017), download public proof-of-concept exploits, and launch attacks on its own. However, the AI never fully broke into any systems during these autonomous runs, instead sampling roughly 100 IP addresses out of a population of over 25,000 n8n instances worldwide.

    The campaign also involved the use of other AI-powered tools, including Qwen, GLM, Kimi, and MiniMax, as well as Western platforms like Claude Code and Codex. The actor's tool configuration suggests that they trusted the Western tools less than the DeepSeek platform, which connected directly to its native APIs without any precautions.

    The researchers behind Unit 42 note that this campaign demonstrates a significant shift in the way attackers are using AI-powered tools to conduct cyberattacks. While most of the systems targeted by DeepSeek were unreachable or non-responsive, the platform was able to find three vulnerable systems and attempt to exploit them automatically.

    "The system executed hundreds of hours of manual targeting analysis in mere minutes," the report states. "This autonomous process of target identification, sampling and narrowing of scope is notable because the system executed hundreds of hours of manual targeting analysis in mere minutes, while also managing its own compute resources."

    The campaign also highlights the importance of building systems with default settings that are tighter than average, as this can prevent attackers from successfully exploiting vulnerabilities.

    "Our findings document a threat actor developing AI-augmented offensive capabilities that enabled them to dramatically increase the speed and scale of their campaigns," concludes the report. "This research validates an emerging threat posed by AI-enabled attackers as they hone their autonomous attack processes to discover, assess, pivot and retarget without human intervention."



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Ai-Powered-Cyberattack-DeepSeek-Autonomous-Hacking-Platform-Uncovered-ehn.shtml

  • https://securityaffairs.com/196544/ai/ai-runs-the-hack-chinese-actor-automates-cyberattacks-with-deepseek.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-33017

  • https://www.cvedetails.com/cve/CVE-2026-33017/


  • Published: Mon Aug 3 11:17:29 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us