Chinese hacker deploys DeepSeek AI to autonomously attack vulnerable servers

A China-based threat actor is using the DeepSeek AI model and open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with minimal human involvement, according to Palo Alto Networks' Unit 42. The researcher, operating under aliases "knaithe" and "KnYuan," configured the agent to accept instructions via Telegram and search for vulnerable systems using the FOFA internet asset search engine.
In a May 2026 session recovered by Unit 42, the agent independently researched vulnerabilities, targeted internet-exposed Langflow and n8n servers, downloaded exploit code, and attempted attacks within minutes—work that would normally require many hours of manual analysis. The agent identified 84 exposed Langflow instances and more than 647,000 n8n instances but failed to compromise any targets, as discovered forms required authentication the attacks could not bypass.
"The workflow confirms a functional, end-to-end autonomous offensive capability," Unit 42 said. The researchers noted the agent operates in "Yolo" mode, executing commands without requesting permission, and that the threat actor also conducted manual attacks against more than 460 systems separately, Lawrence Abrams reports for BleepingComputer.