Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits

August 1, 2026

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

August 1, 2026

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

July 31, 2026
Facebook X (Twitter) Instagram
Saturday, August 1
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
News

Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits

Team-CWDBy Team-CWDAugust 1, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A Chinese threat actor has used large language models (LLMs) from Chinese and Western companies to compromise internet-exposed digital infrastructure in Asia.

In particular, they leveraged one of DeepSeek’s AI models, Hermes Agent, an open-source agentic AI framework, to orchestrate the attack via Telegram.

These AI-augmented offensive capabilities “enabled them to dramatically increase the speed and scale of their campaigns,” said Andy Piazza, senior director of threat intelligence within Unit 42, Palo Alto Networks’ research team, in a report published on July 30.

AI Orchestration and Manual Vulnerability Exploitation

The threat actor is a Chinese-speaking individual operating under the aliases ‘knaithe’ and ‘KnYuan’ and based in Zhuhai, China.

Piazza described them as “an opportunistic exploit operator and self-described binary security researcher” based on the actor’s GitHub activity, specifically their maintenance of 1DayNews, an automated vulnerability intelligence pipeline.

They targeted internet-exposed infrastructure by combining autonomous AI-driven enumeration and automated exploitation with the automated and manual exploitation of seven vulnerabilities.

When initial exploitation failed due to the target environment’s restrictive configurations, the actor’s Hermes Agent, connected to a DeepSeek AI model, autonomously conducted searches for known critical-severity common vulnerabilities and exposures (CVEs). It initially surveyed 10 product families, scanning GitHub for trending proofs of concept (PoC) exploits and prioritizing vulnerabilities by attack surface.

This research led the agent to pivot to seven higher-value vulnerabilities:

  • CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled)
  • CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
  • CVE-2025-68613 (CVSS rating: 9.9): n8n Workflow Automation vulnerability with autonomous exploitation attempt (failed — auth required)
  • CVE-2026-3055 (CVSS rating: 9.8):  Citrix NetScaler ADC & Gateway vulnerability with manual active exploitation (data exfiltrated)
  • CVE-2026-34486 (CVSS rating: 7.5): Apache Tomcat vulnerability with manual active exploitation (reverse shell attempts)
  • CVE-2026-39987 (CVSS rating: 9.8): Marimo Notebook vulnerability with manual active exploitation (command execution confirmed)
  • CVE-2026-0300 (CVSS rating: 9.8): PAN-OS User-ID Authentication Portal vulnerability with manual non-functional research PoC cloned (not executed)
  • CVE-2026-33824 (CVSS rating: 9.8): Windows IKE Extensions (IKE VPN) vulnerability with manual active exploitation (reverse shell attempts)

Evidence of Trial and Testing of AI Tools

In parallel with their use of DeepSeek as their autonomous operator platform, the actor configured multiple LLMs, including Chinese ones (Qwen, GLM, Kimi, MiniMax) and limited usage and testing of Western AI tools, like Claude Code for connectivity testing and proxy validation and OpenAI’s Codex on exploit development directories.

“This limited usage is consistent with evaluating the AI-market to identify their preferred tool set,” Piazza wrote.

While the observed campaign had limited impact and did not achieve full compromise of any of the intended targets, the workflow confirms a functional, end-to-end autonomous offensive capability.

The campaign saw targets spanning three countries, including China and Malaysia, and multiple sectors.

According to Piazza, the main takeway from this campaign lies in the trajectory rather than the outcome.

“The actor is actively iterating – refining tool configurations, developing custom skills, establishing proxy infrastructure and executing autonomous attack cycles. The technical barrier to AI-augmented offensive operations is low and continues to decrease,” the researcher added.

Image credits: PJ McDonnell / ImageFlow / Shutterstock.com

Read now: AI-powered Cyber-Attacks Up Significantly in the Last Year, Warns CrowdStrike



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Team-CWD
  • Website

Related Posts

News

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

August 1, 2026
News

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

July 31, 2026
News

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

July 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What’s at stake if your employees post too much online

December 1, 2025

How cybercriminals are targeting content creators

November 26, 2025

Don’t let “back to school” become “back to bullying”

September 11, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.