Close Menu
NCIJ Network NCIJ Network
    What's Hot

    YouTuber Hank Green says his AI usage is ‘not healthy’

    August 1, 2026

    Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

    August 1, 2026

    CZ Warns Bitcoin Holders After $70 Million Wallet Exploit: ‘Nothing Is 100%’

    August 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • YouTuber Hank Green says his AI usage is ‘not healthy’
    • Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
    • CZ Warns Bitcoin Holders After $70 Million Wallet Exploit: ‘Nothing Is 100%’
    • Tiny black holes may be secretly exploding stars across the Milky Way
    • The hill I will die on: Games are the opposite of fun, and I’d ban them for anyone over 12 | Emily Watkins
    • Palestinian children among those detained in Israeli West Bank raids | Occupied West Bank News
    • In Dropping Reflecting Pool Case, Pirro Draws Trump’s Wrath
    • Best Organic Mattresses (2026): Certified Nontoxic, Natural Sleep
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 1, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 31, 2026Artificial Intelligence / Cyber Attack

    Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.

    After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session.

    The operator, tracked through the aliases knaithe and KnYuan, launched exploitation attempts against more than 460 targets using autonomous and conventional workflows.

    Unit 42 described seven exploit tracks. They span eight Common Vulnerabilities and Exposures (CVE) identifiers because the n8n chain combines two vulnerabilities. The DeepSeek-led attacks against Langflow and n8n failed because the exposed systems did not meet the exploits’ configuration requirements.

    In separate manual operations, Unit 42 reported data exfiltration from three organizations through the NetScaler memory-overread flaw CVE-2026-3055 and command execution on 11 Marimo instances through CVE-2026-39987. Yet it later says it could confirm only three successfully exploited targets across the entire operation. The report does not reconcile the two statements. The Hacker News has contacted Palo Alto Networks for clarification and will update the story with any response.

    Cybersecurity

    The agent checked versions, downloaded exploits, abandoned an unproductive path, and chose another vulnerability based on severity, deployment scale, and apparent exploitability. Organizations should patch exposed Langflow, n8n and Marimo systems, along with customer-managed NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers. They should also remove unnecessary public access to workflow and notebook interfaces.

    Hermes Agent exposed the operation by starting python3 -m http.server 8888 from /home/worker. The unintended HTTP server made the actor’s model configurations, application programming interface (API) keys, exploit scripts, target lists, shell history, and autonomous-session logs accessible, according to the company’s report.

    DeepSeek was the primary reasoning model inside Hermes Agent, which supplied terminal access, reusable skills and unattended execution. Unit 42 found limited use of Claude Code and Qwen Code. It also found signs of Codex use in exploit-development directories, but could not verify actual use because the chat logs were not preserved.

    The framework’s own documentation confirms that it can operate through Telegram, run commands, and schedule unattended tasks.

    In a recovered May 2026 session, DeepSeek downloaded a public exploit for the Langflow code-injection flaw CVE-2026-33017, enumerated 84 instances through FOFA, and found one target running version 1.3.4. Langflow is an artificial intelligence (AI) agent and workflow builder. The attack stopped because the system had neither auto_login enabled nor a usable public flow identifier.

    The agent then surveyed 10 product families, searched GitHub for recent proof-of-concept repositories and selected n8n, the workflow automation platform. It obtained a chain combining the unauthenticated file-access flaw CVE-2026-21858 with the expression-injection issue CVE-2025-68613. FOFA returned 25,209 n8n systems in China during the session.

    Cybersecurity

    DeepSeek sampled about 100, probed roughly 40 and identified three running vulnerable versions. One target exposed three form endpoints, but all required authentication. More than 50 additional targets also lacked a usable public form, so no n8n system was compromised.

    Langflow fixed CVE-2026-33017 in version 1.9.0. n8n fixed CVE-2026-21858 in version 1.121.0. It fixed CVE-2025-68613 in versions 1.120.4, 1.121.1, and 1.122.0. Version 1.121.1 is therefore the earliest release that addresses both flaws used in the attempted chain. Marimo fixed CVE-2026-39987 in version 0.23.0.

    Citrix says CVE-2026-3055 affects customer-managed NetScaler ADC and Gateway appliances configured as SAML identity providers. Administrators can check the appliance configuration for add authentication samlIdPProfile .* and install the fixed builds listed in the company’s security bulletin.

    Unit 42 assesses the operator to be based in Zhuhai, China. Public material is consistent with, but does not independently verify, that assessment: the GitHub profile displays the name “KnYuan Knaithe,” while an older blog under the same handle describes its author as a binary security researcher in Zhuhai. Those profiles do not establish the operator’s legal identity or any state connection.

    attacks autonomous Chinese Commands DeepSeek Hacker launch Telegram
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

    Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

    6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

    Rails patches critical Active Storage flaw with RCE potential

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    YouTuber Hank Green says his AI usage is ‘not healthy’

    August 1, 2026

    Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

    August 1, 2026

    CZ Warns Bitcoin Holders After $70 Million Wallet Exploit: ‘Nothing Is 100%’

    August 1, 2026

    Tiny black holes may be secretly exploding stars across the Milky Way

    August 1, 2026
    Latest Posts

    Wildfires ravage Spain, France and Italy, killing three firefighters

    July 23, 2026

    Three speeches on a single day signaled a dying American democracy | Robert B Shpiner

    July 23, 2026

    Keystone clashes: Millions pour into three Pennsylvania races that could decide control of the House • OpenSecrets

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    YouTuber Hank Green says his AI usage is ‘not healthy’

    August 1, 2026

    Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

    August 1, 2026

    CZ Warns Bitcoin Holders After $70 Million Wallet Exploit: ‘Nothing Is 100%’

    August 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.