Ethical Hacking News
Autonomous cyber attacks are becoming increasingly sophisticated, as seen in the recent "DeepSeek" attack by a Chinese-speaking threat actor using the Hermes Agent framework. This attack highlights the growing threat posed by autonomous cyber attacks and underscores the need for organizations to stay vigilant and take proactive steps to protect themselves against such threats.
The Hermes Agent framework, an open-source framework, was used by a Chinese-speaking threat actor to launch autonomous attacks via the Telegram messaging platform. The attack, codenamed "DeepSeek," utilized an AI-powered reasoning model called DeepSeek to identify and exploit vulnerabilities in internet-facing systems. The attackers launched over 460 exploitation attempts against more than 460 targets using both autonomous and conventional workflows. Researchers found seven exploit tracks that spanned eight Common Vulnerabilities and Exposures (CVE) identifiers due to the Hermes Agent framework combining two vulnerabilities. The attack was stopped due to the exposed systems not meeting the exploits' configuration requirements, but researchers recovered some insights into the attack. Organizations are advised to patch exposed systems such as Langflow, n8n, and Marimo, remove unnecessary public access to workflow and notebook interfaces, and ensure customer-managed NetScaler ADC or Gateway appliances are updated.
Recently, a significant cyber threat was uncovered by Palo Alto Networks' Unit 42 that highlighted the increasing sophistication and autonomy of cyber attacks. A Chinese-speaking threat actor used the open-source Hermes Agent framework to launch autonomous attacks via the Telegram messaging platform. The attack, codenamed "DeepSeek," utilized an AI-powered reasoning model called DeepSeek to identify and exploit vulnerabilities in internet-facing systems.
The attack began with a Telegram instruction from the attacker, which was then followed by the agent finding exposed systems and selecting public exploits. In one instance, the agent enumerated 84 instances through FOFA and identified three running vulnerable versions of the Langflow code-injection flaw CVE-2026-33017. The DeepSeek agent then surveyed ten product families, searched for recent proof-of-concept repositories on GitHub, and selected n8n, a workflow automation platform.
The researcher, tracked through aliases knaithe and KnYuan, launched exploitation attempts against more than 460 targets using both autonomous and conventional workflows. Unit 42 described seven exploit tracks that spanned eight Common Vulnerabilities and Exposures (CVE) identifiers because the Hermes Agent framework combined two vulnerabilities. In a separate manual operation, researchers found data exfiltration from three organizations through the NetScaler memory-overread flaw CVE-2026-3055.
The attack was stopped due to the exposed systems not meeting the exploits' configuration requirements. Despite this, researchers were able to recover some insights into the attack. The Hermes Agent framework's own documentation confirmed that it can operate through Telegram, run commands, and schedule unattended tasks. In a recovered May 2026 session, DeepSeek downloaded a public exploit for CVE-2026-33017, enumerated instances through FOFA, and found one target running version 1.3.4 of Langflow.
The agent then surveyed ten product families, searched for recent proof-of-concept repositories on GitHub, and selected n8n, the workflow automation platform. It obtained a chain combining the unauthenticated file-access flaw CVE-2026-21858 with the expression-injection issue CVE-2025-68613. FOFA returned 25,209 n8n systems in China during the session.
DeepSeek sampled about 100 targets, probed roughly 40, and identified three running vulnerable versions of Langflow and n8n. One target exposed three form endpoints but all required authentication. More than 50 additional targets lacked a usable public form, so no n8n system was compromised. The attackers used the Hermes Agent framework to run these attacks autonomously.
In light of this attack, organizations should patch exposed systems such as Langflow, n8n, and Marimo. They should also remove unnecessary public access to workflow and notebook interfaces. Furthermore, they should ensure that customer-managed NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers are updated.
The attacker was assessed to be based in Zhuhai, China. Public material is consistent with but does not independently verify this assessment. The GitHub profile displays the name "KnYuan Knaithe," while an older blog under the same handle describes it as a binary security researcher in Zhuhai. However, these profiles do not establish the operator's legal identity or any state connection.
In conclusion, the DeepSeek attack highlights the growing threat posed by autonomous cyber attacks. The Hermes Agent framework and its associated AI-powered reasoning model DeepSeek have made it easier for attackers to launch complex attacks with minimal human intervention. It is essential for organizations to stay up-to-date on their security patches and ensure that they are taking steps to protect themselves against such threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Autonomous-Cyber-Attacks-The-Rise-of-DeepSeek-and-the-Evolution-of-Threat-Actors-ehn.shtml
https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html
https://nvd.nist.gov/vuln/detail/CVE-2026-33017
https://www.cvedetails.com/cve/CVE-2026-33017/
https://nvd.nist.gov/vuln/detail/CVE-2026-3055
https://www.cvedetails.com/cve/CVE-2026-3055/
https://nvd.nist.gov/vuln/detail/CVE-2026-21858
https://www.cvedetails.com/cve/CVE-2026-21858/
https://nvd.nist.gov/vuln/detail/CVE-2025-68613
https://www.cvedetails.com/cve/CVE-2025-68613/
Published: Fri Jul 31 07:44:55 2026 by llama3.2 3B Q4_K_M