Hacker Deploys DeepSeek AI for Autonomous Cyberattacks on Exposed Servers
A Chinese-speaking threat actor uses the DeepSeek AI model alongside the open-source Hermes Agent framework to autonomously attack vulnerable internet-exposed servers with minimal human involvement. Palo Alto Networks' Unit 42 researchers discover the campaign after Hermes accidentally exposes its home directory, leaking API keys, exploit scripts, target lists, shell history, and AI attack logs. The activity is attributed to a China-based operator using the aliases "knaithe" and "KnYuan," who identifies as a binary security researcher.
The Hermes Agent integrates with the FOFA internet asset search engine and accepts instructions through a Telegram channel, while DeepSeek serves as its reasoning engine. A recovered session from May 2026 reveals that the operator provides only an initial task, after which the agent operates fully autonomously. The agent identifies 84 exposed Langflow servers vulnerable to CVE-2026-33017, and when those targets prove unexploitable, it independently searches for new vulnerabilities and shifts focus to the n8n automation platform with over 647,000 exposed instances.
Although the observed attacks do not successfully compromise any targeted servers, Unit 42 warns that the campaign demonstrates a functional end-to-end autonomous offensive capability. The AI workflow can discover, evaluate, and attack vulnerable systems without human feedback, representing a significant escalation in automated cyber threats. As AI models become more accessible and capable, security experts anticipate that autonomous attack frameworks will increasingly lower the barrier for conducting sophisticated campaigns at scale.