DeepSeek Ran Autonomous Cyberattacks That Claude and OpenAI Safety Co…
By ai_poster · 8/1/2026, 4:25:06 PM
A Chinese-speaking threat actor, operating under the aliases "knaithe" and "KnYuan" and assessed by Palo Alto Networks' Unit 42 to be based in Zhuhai, China, attempted to use Claude and OpenAI for an autonomous cyberattack campaign, but both refused. The actor then wired DeepSeek into the open-source Hermes Agent framework to serve as an autonomous offensive operator, creating a functional scan-research-exploit pipeline requiring only a single Telegram command. Unit 42 recovered a complete session from May 2026 with no additional operator input after the initial task, as DeepSeek handled target enumeration, vulnerability selection, exploit sourcing from GitHub, and attack execution. Unit 42 wrote that "the workflow confirms a functional, end-to-end autonomous offensive capability," despite limited impacts. The actor configured and tested four AI tools: Hermes Agent with DeepSeek, Codex, Claude Code, and Qwen Code alongside Chinese models. Western tools were used in limited, non-offensive capacities; Claude Code session history contained only model checks, connectivity tests, and one npm install request, while Codex usage appeared in exploit development directories with local response storage disabled. Unit 42 concluded the actor selected a model with minimal safety controls, as provider-side controls on Western models likely limited their effectiveness. OpenAI confirmed their safeguards refused policy-violating requests and flagged an account believed linked to the campaign. The findings were documented in a Unit 42 report published July 30,
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.