Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    CISA warns of cyberattacks disrupting U.S. water utilities

    August 1, 2026

    Hacker uses DeepSeek AI to autonomously attack vulnerable servers

    August 1, 2026

    Rails patches critical Active Storage flaw with RCE potential

    August 1, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Hacker uses DeepSeek AI to autonomously attack vulnerable servers
    News

    Hacker uses DeepSeek AI to autonomously attack vulnerable servers

    adminBy adminAugust 1, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Malicious AI agent

    A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement.

    The activity was discovered by Palo Alto Networks’ Unit 42 researchers after Hermes accidentally created a web server from its home directory, exposing the attacker’s environment, including API keys, exploit scripts, target lists, shell history, and AI attack logs.

    Unit 42 attributed the activity to a China-based threat actor operating under the aliases “knaithe” and “KnYuan,” who calls themself a “binary security researcher.”

    image

    While the autonomous attacks observed by Unit 42 did not successfully compromise the targeted servers, the researchers say the campaign illustrates an offensive AI workflow capable of discovering, evaluating, and attacking vulnerable systems.

    “While the observed campaign had limited impacts, the workflow confirms a functional, end-to-end autonomous offensive capability,” Unit 42 said.

    DeepSeek used for autonomous attacks

    The threat actor used DeepSeek as the reasoning engine behind Hermes Agent, an open-source AI framework capable of interacting with operating system terminals, running commands, and connecting to the internet.

    The agent supports a “Yolo” mode that allows it to operate and execute commands, even risky ones, without first requesting permission from its operator.

    Hermes was configured to accept instructions from a Telegram channel, use custom offensive-security skills, and integrate with the FOFA internet asset search engine.

    Unit 42 recovered a May 2026 session in which the operator appears to have provided only an initial task, after which the agent conducted the remaining activity autonomously without human feedback.

    The agent first targeted internet-exposed Langflow servers vulnerable to CVE-2026-33017, downloading a public proof-of-concept exploit, identifying 84 exposed instances through FOFA, and scanning them for vulnerable configurations.

    After determining that the available targets could not be exploited, the agent searched for other potential vulnerabilities to scan for vulnerable devices.

    DeepSeek then analyzed multiple public exploit repositories before selecting the n8n workflow automation platform to target, which had more than 647,000 exposed instances identified through FOFA.

    The agent downloaded an exploit that chained CVE-2026-21858 and CVE-2025-68613, identified servers running vulnerable versions, and checked them for unauthenticated file-upload forms required to complete the attack.

    However, the discovered forms required authentication, and Unit 42 says the autonomous attempts failed to compromise any targets.

    Unit 42 says the campaign is significant because the agent independently researched vulnerabilities, determined which targets were the best option, downloaded exploit code, and then attempted to exploit found targets in minutes what would normally take many hours.

    “This autonomous process of target identification, sampling and narrowing of scope is notable because the system executed hundreds of hours of manual targeting analysis in mere minutes, while also managing its own compute resources,” explained Palo Alto.

    While the AI agent was used extensively, the threat actor also conducted manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products.

    Unit 42 confirmed three successful compromises targeting the Citrix NetScaler vulnerability CVE-2026-3055, which the actor used to extract memory and search for authentication cookies that could be used to hijack sessions.

    The actor had also configured other AI coding platforms, including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI’s Codex, but Unit 42 found that they were not used often.

    Autonomous AI attack flow
    Autonomous AI attack flow
    Source: Palo Alto Unit 42

    Hermes used in previous cyberattack

    The exposed AI campaign comes after another recently disclosed incident in which poorly secured Hermes infrastructure exposed details about an alleged cyberattack against Thailand’s Ministry of Finance.

    Last week, BleepingComputer reported that Hunt.io and security researcher Bob Diachenko discovered open web directories containing exploit tools, web shells, credentials, compiled payloads, and Hermes activity logs.

    Those logs showed Hermes running in unattended “YOLO” mode to automate post-exploitation activity, including searching for privilege-escalation opportunities, enumerating services, inspecting containers, traversing filesystems, and cataloging documents stored on Ministry of Finance systems.

    However, the earlier incident did not show Hermes independently choosing the target or determining how to compromise it.

    A human operator supplied the target, objectives, and attack tools, while Hermes automated routine activity after access had apparently already been obtained.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleRails patches critical Active Storage flaw with RCE potential
    Next Article CISA warns of cyberattacks disrupting U.S. water utilities
    admin
    • Website

    Related Posts

    News

    CISA warns of cyberattacks disrupting U.S. water utilities

    August 1, 2026
    News

    Rails patches critical Active Storage flaw with RCE potential

    August 1, 2026
    News

    A Hidden ‘Dark Dimension’ Could Rewrite Our Understanding of the Universe

    August 1, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202639 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202635 Views
    Our Picks

    CISA warns of cyberattacks disrupting U.S. water utilities

    August 1, 2026

    Hacker uses DeepSeek AI to autonomously attack vulnerable servers

    August 1, 2026

    Rails patches critical Active Storage flaw with RCE potential

    August 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.