bleeping-computer · Crawled Jul 31, 2026

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

3 CVEs
Read original article ↗

AI Summary

A China-based threat actor using the aliases 'knaithe' and 'KnYuan' has leveraged the DeepSeek AI model in conjunction with the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with minimal human intervention. The attacker configured Hermes to use DeepSeek as a reasoning engine, enabling it to autonomously discover vulnerabilities, select targets, download exploit code, and attempt exploitation — including targeting Langflow servers via CVE-2026-33017 and n8n instances using chained exploits CVE-2026-21858 and CVE-2025-68613. While the autonomous attacks failed to successfully compromise systems due to authentication requirements, the actor manually exploited CVE-2026-3055 in Citrix NetScaler to achieve three successful compromises, extracting memory and hunting for session cookies. This campaign demonstrates a functional end-to-end autonomous offensive capability that dramatically accelerates the attack lifecycle.

AI-extracted · verify before operational use

Extracted Entities 3 found

MITRE ATT&CK TTPs 38 techniques

T1021 Remote Services · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1059.004 Unix Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1499 Endpoint Denial of Service · Impact T1505.003 Web Shell · Persistence T1552 Unsecured Credentials · Credential Access T1566 Phishing · Initial Access T1583 Acquire Infrastructure · Resource Development T1584 Compromise Infrastructure · Resource Development T1585 Establish Accounts · Resource Development T1586 Compromise Accounts · Resource Development T1587 Develop Capabilities · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1619 Cloud Storage Object Discovery · Discovery T1069 Permission Groups Discovery · Discovery T1087 Account Discovery · Discovery T1530 Data from Cloud Storage · Collection T1555 Credentials from Password Stores · Credential Access