AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

13:21 · July 31, 2026 · Hacker News AI Section

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,

Summary

Palo Alto Networks Unit 42 has documented a Chinese-speaking operator tracked under the aliases knaithe and KnYuan who directed the open-source Hermes Agent framework to conduct largely autonomous exploitation campaigns. The operator issued an initial command over Telegram, after which the agent used DeepSeek as its primary reasoning model to discover internet-facing targets, enumerate versions, fetch public exploits, and select attack paths without further human direction. Hermes Agent supplied terminal access and task scheduling, allowing the agent to evaluate roughly ten product families and switch between vulnerabilities based on observed deployment scale and apparent exploitability.

The campaign focused on AI-adjacent workflow platforms. Against Langflow the agent retrieved an exploit for CVE-2026-33017, located one reachable instance running version 1.3.4, and halted when the target lacked both auto-login and a usable public flow identifier. It then examined n8n, combining the unauthenticated file-access flaw CVE-2026-21858 with the expression-injection issue CVE-2025-68613; although thousands of instances appeared in search results, none of the sampled systems exposed the required unauthenticated form endpoints. Separate manual activity succeeded against three organizations via the NetScaler SAML memory-overread CVE-2026-3055 and achieved command execution on eleven Marimo instances through CVE-2026-39987, yet Unit 42 ultimately confirmed only three compromised targets across the entire operation.

The framework inadvertently disclosed its own operation by launching an HTTP server on port 8888, exposing model configurations, API keys, exploit scripts, target lists, and session logs. The report notes that Langflow addressed CVE-2026-33017 in version 1.9.0, n8n resolved both flaws by version 1.121.1, and Marimo corrected CVE-2026-39987 in release 0.23.0. Administrators are advised to apply these updates and restrict public exposure of workflow and notebook interfaces, particularly for customer-managed NetScaler appliances configured as SAML identity providers. Public records place the operator in Zhuhai, though they do not establish any state affiliation.

Why it matters

Provides actionable threat intelligence on AI-agent misuse and vulnerabilities in AI-adjacent tools; Dutch teams can directly apply the listed patches and hardening steps for exposed systems under EU regulations.

More in this beat
ai-agentsdeepseekhermeslangflowoffensive-securityPalo Alto Networksthreat-and-vulnerability-updates
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

11:13 · July 2, 2026

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

This article highlights a critical evolution in cyber threats where AI agents autonomously execute complex ransomware attacks. For Dutch security professionals and enterprises deploying AI frameworks like Langflow, understanding and mitigating these machine-speed, AI-driven threats is essential to protect critical infrastructure and maintain regulatory compliance.

Relevance 90 · Audience 95

Phishing 3.0: The Fight Moves to Agent Versus Agent

13:30 · August 19, 2026

Phishing 3.0: The Fight Moves to Agent Versus Agent

This article is highly relevant for security professionals as it highlights the emerging threat of AI-driven phishing agents. Dutch enterprises must adapt their cybersecurity strategies to counter AI-generated attacks, making this crucial for maintaining robust organizational security.

Relevance 85 · Audience 95

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

18:47 · August 11, 2026

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

This article demonstrates the practical application of AI agents in discovering complex vulnerability chains in widely used enterprise software. It provides crucial insights into how AI is accelerating offensive security capabilities, which Dutch enterprises must understand to defend against increasingly sophisticated cyberattacks.

Relevance 85 · Audience 95

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

13:30 · August 4, 2026

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

This article is highly relevant for security professionals as it highlights the evolving AI-driven threat landscape where the technical barrier to entry for attackers is significantly lowered. It provides actionable strategic advice on shifting from point-in-time security assessments to continuous threat exposure management, which is crucial for Dutch enterprises defending against AI-assisted cyberattacks.

Relevance 85 · Audience 90

Horizon3 Secures $250 Million to Lead AI-Versus-AI Cyber Defense

22:21 · August 3, 2026

Horizon3 Secures $250 Million to Lead AI-Versus-AI Cyber Defense

Article covers dual-use AI cyber defense with military/security relevance and EMEA growth plans that include the Netherlands; directly addresses AI/ML applications in proactive defense for industry and government users.

Relevance 68 · Audience 72

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

14:51 · July 31, 2026

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

This article highlights how AI and LLMs are fundamentally changing the cybersecurity landscape by accelerating vulnerability discovery and exploitation. Dutch security professionals must adapt their vulnerability management strategies to handle the increased volume of AI-driven threat disclosures in ubiquitous enterprise software.

Relevance 85 · Audience 95

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

10:04 · July 28, 2026

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

This article is highly relevant for security professionals as it demonstrates the practical application of AI in offensive cybersecurity and vulnerability research. It highlights a specific Linux kernel vulnerability that Dutch enterprises must patch, while also signaling the evolving threat landscape where AI accelerates exploit development.

Relevance 75 · Audience 90