Forkast.News DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor
Article Content
- •The campaign involved over 460 attempted attacks using DeepSeek AI and Hermes Agent.
- •Only three successful compromises were confirmed, primarily involving data exfiltration from Citrix NetScaler.
- •OpenAI's safety controls effectively blocked the threat actor's attempts to use their models for offensive tasks.
A Chinese-speaking threat actor, identified as knaithe/KnYuan, executed an autonomous cyberattack campaign using DeepSeek AI and the Hermes Agent framework. The campaign targeted over 460 servers, attempting to exploit multiple vulnerabilities, including CVE-2026-33017 and CVE-2026-21858. The attacks were conducted with minimal human intervention, as the AI autonomously handled target enumeration and exploit execution. Although the campaign did not successfully compromise most targets, it marks a significant shift in offensive cyber operations, showcasing the potential of AI in autonomous hacking. The operation was exposed when Hermes accidentally launched a public HTTP server, leaking sensitive information. Unit 42 confirmed that safety controls from OpenAI and Claude Code effectively blocked the actor's attempts to use those models, leading to the selection of DeepSeek due to its lack of guardrails. The incident highlights the operational value of AI safety controls in preventing misuse.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (15)
Following this threat?
Track Knaithe, OpenAI and CVE-2025-68613 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical RCE Vulnerability in n8n Disclosed (CVE-2025-68613) CVE-2025-68613 is a critical remote code execution (RCE) vulnerability found in n8n, an open-source workflow automation platform. This flaw allows authenticated users to execute arbitrary code on the server, risking full system compromise. The CVSS score for this vulnerability is 9.9 to 10.0, indicating its severity.…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…