CVE
CVE-2026-39987
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Exploitation IoCs 39
Domain *[.]trycloudflare[.]com
Domain api[.]deepseek[.]com
Domain cdnorigin[.]net
Domain code[.]newcli[.]com
Domain dashscope[.]aliyuncs[.]com
Filename /dev/shm/.n4d
Filename /etc/cron.d/.sys-health
Filename /etc/profile.d/.sys_alias.sh
Filename /etc/systemd/system/sys-resource.service
Filename /home/worker
Filename /tmp/.n4d_autodeploy_debug
Filename /tmp/.sys-health-monitor.tmp
Filename /var/tmp/.a
Filename /var/tmp/.wd
Filename fofoapi.py
Filename http.server
Filename langflow_poc.py
Filename python3 -m http.server 8888
GitHub Repo Chocapikk/CVE-2026-21858
GitHub Repo Hermes Agent
GitHub Repo n4d-agent/loader
GitHub Repo oscar-mine/CVE-2026-33017
GitHub Repo qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC
GitHub User KnYuan
GitHub User knaithe
SHA-1 31c69b3e12936abca770d430066f379ec1d997ec
SHA-256 0d5f67b6d35e609e1d5eac0afd981147ea8df7da2f192ae59ac0bab7e48cc1de
SHA-256 3435cc9d4a255bfb4cfb09f2390c29b888f70a43345cfaaecf46c55bc89b814d
SHA-256 749e8835bb407336742f3fff5f81ba5eb476a42dfc0246f1107d4f28f1bea708
SHA-256 77fe750d6b94b32e80e25aecb2ae7c435f0b45cfca25969dbee4dc22967b1302
SHA-256 79e44b8523ee1e371436ca36e91d4d6f932beb371e7d77de756ffdd8f825e763
SHA-256 94ae566e27b176698958b4b9c216a0a2b0ac7ce11d7d81417c8add081fd3cc9c
SHA-256 c422621ef824b627d74906f8d75ed8f990f4d6c708a0d263f219f9d9dd435174
SHA-256 d4483b7a943faeec2ce6690e508ee3a30c7fc1e546887658921c132f179b8e78
SHA-256 e09ac5e8c23a768a2370cff29aca64be0d6e210e1176ee526bb7e47f537509ae
SHA-256 fc4109f5dd1d30b65dd60e57dc639ac1d313bfa5241e36e61fbc4aabc1cda482
IP 209[.]99[.]186[.]235
IP 209[.]99[.]186[.]73
Registry User n4d-2ff16c75b1d2
MITRE ATT&CK TTPs 16
T1021 T1059 T1059.001 T1071.001 T1078 T1078.001 T1090 T1133 T1190 T1210 T1220 T1484 T1485 T1566 T1588.001 T1659
Remote Services
Lateral Movement
Command and Scripting Interpreter
Execution
PowerShell
Execution
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
Default Accounts
Defense Evasion
Proxy
Command And Control
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Exploitation of Remote Services
Lateral Movement
XSL Script Processing
Defense Evasion
Domain or Tenant Policy Modification
Defense Evasion
Data Destruction
Impact
Phishing
Initial Access
Malware
Resource Development
Content Injection
Initial Access
Source Articles
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled "go-titan," and how to hunt for it
The N4D Mesh Controller is an active Linux malware campaign that exploits exposed Model Context Protocol (MCP) servers to enable credential theft, lateral movement, persistence, and command and control. The campaign uses a UPX-packed Go-based agent named 'go-titan' that communicates with controllers via custom headers and supports secondary C2 through Cloudflare Quick Tunnels. The agent targets AI and infrastructure services including Ray Dashboard, LightLLM, PostgreSQL, Redis, Kubernetes, and Jenkins, using automated scanning and exploitation techniques.
datadog-security-labs Aug 20, 2026
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. These include a critical remote code execution flaw in Langflow (CVE-2026-9198), a sensitive data encryption bypass in Apache Tomcat (CVE-2026-34486), and an authentication bypass in N-able N-central (CVE-2026-18556 and CVE-2026-18577). Exploitation of CVE-2026-34486 has been linked to a Chinese-speaking threat actor using the aliases knaithe and KnYuan, who leveraged AI-powered offensive tools like DeepSeek via the Hermes Agent framework to autonomously target internet-exposed systems. The actor combined autonomous reconnaissance with manual exploitation of known vulnerabilities in Citrix NetScaler, Marimo, and IKE VPN, among others, targeting over 460 organizations.
hacker-news Aug 5, 2026
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
A Chinese-speaking threat actor using the aliases knaithe and KnYuan leveraged the open-source Hermes Agent framework, powered by DeepSeek as the primary reasoning model, to autonomously conduct cyberattacks. The actor issued initial commands via Telegram, after which the agent independently identified internet-facing systems, selected public exploits, and attempted exploitation without further input. The campaign targeted vulnerabilities in Langflow, n8n, Marimo, and Citrix NetScaler systems, with confirmed exploitation of CVE-2026-3055 and CVE-2026-39987, though only three systems were successfully compromised. The operation was exposed due to an unintentional HTTP server exposing configuration files, API keys, exploit scripts, and logs.
hacker-news Jul 31, 2026
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has launched an AI-powered autonomous hacking campaign leveraging the Hermes Agent framework with DeepSeek as a reasoning engine to exploit seven critical vulnerabilities in Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, Palo Alto PAN-OS, and Microsoft Windows IKE Extensions. The campaign uses AI models to autonomously conduct vulnerability assessment, target selection, and exploit generation, with command and control coordinated via Telegram. The actor also leverages publicly available AI tools like Claude Code, Codex, and Qwen Code to support operations. When initial exploitation fails, the system automatically searches for new critical CVEs using GitHub PoCs to prioritize attack surfaces.
hacker-news Jul 30, 2026
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 identified a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan who conducted an AI-enabled autonomous cyberattack campaign. The actor used the Hermes Agent framework with DeepSeek as the reasoning engine to autonomously enumerate vulnerabilities, acquire exploit code, and launch attacks without human intervention. They targeted multiple vulnerabilities including CVE-2026-33017 in Langflow and chained CVEs in n8n (CVE-2026-21858 and CVE-2025-68613), though exploitation attempts failed due to configuration requirements. Manual operations successfully exploited CVE-2026-3055 in Citrix NetScaler, leading to confirmed data exfiltration. The campaign was exposed when the actor accidentally exposed their infrastructure via an HTTP file server.
unit42 Jul 30, 2026
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go-based botnet named NadMesh, discovered in early July 2026, actively targets exposed AI and cloud services to harvest cloud credentials, Kubernetes tokens, and model access. The malware prioritizes exploitation of MCP (Model Context Protocol) services, Docker APIs, Jenkins consoles, and Redis instances, with a focus on credential theft rather than host compromise. The operator uses self-propagating scanning infrastructure, persistence mechanisms, and obfuscation to evade detection, while targeting specific ports associated with AI tools like ComfyUI, Ollama, Gradio, and n8n. Researchers observed real-time exploitation traffic, though success rates for MCP exploitation remain low compared to other vectors.
hacker-news Jul 17, 2026