DeepSeek Ran Autonomous Attacks on 460+ Targets

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Unit 42 reported a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to autonomously launch attacks after an initial Telegram instruction, with researchers recovering no further operator input in the session.
- The operator, tracked via aliases knaithe and KnYuan, launched exploitation attempts against more than 460 targets across seven exploit tracks spanning eight CVEs, though Unit 42 confirmed only three successfully exploited targets across the entire operation.
- DeepSeek served as the primary reasoning model inside Hermes Agent, enabling the agent to check versions, download exploits, abandon unproductive paths, and select vulnerabilities based on severity, deployment scale, and apparent exploitability.
- The DeepSeek-led attacks against Langflow (CVE-2026-33017) and n8n (CVE-2026-21858 chained with CVE-2025-68613) failed because exposed systems didn't match configuration requirements — FOFA returned 25,209 n8n systems in China during one session, but none were compromised.
- In separate manual operations, data was exfiltrated from three organizations via the NetScaler memory-overread flaw CVE-2026-3055 and command execution achieved on 11 Marimo instances via CVE-2026-39987, though the report does not reconcile the Marimo count with the three-target overall confirmation.
- Hermes Agent exposed the operation by accidentally starting python3 -m http.server 8888 from /home/worker, making the actor's API keys, exploit scripts, target lists, shell history, and model configurations publicly accessible.
- Unit 42 assesses the operator is based in Zhuhai, China, based on a GitHub profile and older blog under the handle KnYuan Knaithe, but those profiles do not establish the operator's legal identity or any state connection.
Why it matters: The operation shows how open-source AI agent frameworks compress attack chains: one Telegram instruction triggered autonomous scanning of 460+ targets with minimal human oversight. Three confirmed breaches and Hermes Agent's accidental exposure of API keys and target lists reveal how quickly such operations can spiral out of the operator's control.
Ask SkimNews



