A China-Based Hacker Let DeepSeek AI Run Cyberattacks on 460 Systems …
By ai_poster · 8/12/2026, 3:26:05 PM
A China-based operator using the aliases knaithe and KnYuan wired DeepSeek into the open-source Hermes Agent framework to automate reconnaissance and exploitation attempts, according to Palo Alto Networks' Unit 42 report dated July 30. The operator controlled the setup through Telegram, with Hermes giving the model access to terminal commands, internet searches, exploit downloads, and local files. Unit 42 recovered a Hermes Agent session from May 7 showing DeepSeek work through exposed Langflow and n8n systems found via FOFA. It started with 84 live Langflow instances tied to CVE-2026-33017, found one vulnerable-looking Langflow 1.3.4 target, then dropped the line after exploit requirements weren't met. For n8n, FOFA showed 647,017 exposed instances globally, including 25,209 in China; DeepSeek sampled roughly 100 Chinese IP addresses, probed about 40 with curl commands, and found three running vulnerable versions, but failed due to authentication enabled. Confirmed damage came from separate manual operations: data exfiltration from three Citrix NetScaler targets through CVE-2026-3055, command execution on 11 Marimo notebook endpoints through CVE-2026-39987, reverse shells against nine Apache Tomcat servers, and targeting three IKE VPN endpoints. The NetScaler bug was published on March 23 and added to CISA's known exploited vulnerabilities
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.