Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
AI Summary
A Chinese-speaking threat actor using the aliases knaithe and KnYuan leveraged the open-source Hermes Agent framework, powered by DeepSeek as the primary reasoning model, to autonomously conduct cyberattacks. The actor issued initial commands via Telegram, after which the agent independently identified internet-facing systems, selected public exploits, and attempted exploitation without further input. The campaign targeted vulnerabilities in Langflow, n8n, Marimo, and Citrix NetScaler systems, with confirmed exploitation of CVE-2026-3055 and CVE-2026-39987, though only three systems were successfully compromised. The operation was exposed due to an unintentional HTTP server exposing configuration files, API keys, exploit scripts, and logs.
AI-extracted · verify before operational use