Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
AI Analysis
Technical Summary
The threat actor leverages DeepSeek as the reasoning engine behind Hermes Agent, an AI framework capable of executing OS commands and internet interactions autonomously. Hermes was configured to operate in a 'Yolo' mode, executing commands without operator approval, and integrated with the FOFA internet asset search engine to identify exposed servers. The agent autonomously scanned for vulnerabilities such as CVE-2026-33017 in Langflow servers and a chained exploit involving CVE-2026-21858 and CVE-2025-68613 targeting the n8n platform. Despite extensive autonomous attempts, no successful compromises were observed from these AI-driven attacks. However, manual attacks by the actor exploited vulnerabilities including CVE-2026-3055 in Citrix NetScaler, resulting in at least three confirmed compromises. The campaign highlights an AI-driven workflow capable of rapid target identification, exploit selection, and attack execution, significantly reducing the time required for manual analysis.
Potential Impact
The autonomous AI attack workflow accelerates the reconnaissance and exploitation phases of cyberattacks, enabling rapid identification and targeting of vulnerable systems. While the autonomous attacks observed did not result in successful compromises, the actor's manual attacks achieved confirmed breaches, including session hijacking via Citrix NetScaler vulnerabilities. This demonstrates the potential for AI-driven tools to enhance attacker efficiency and scale, increasing the risk of rapid exploitation of newly discovered vulnerabilities.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisories for CVE-2026-33017, CVE-2026-21858, CVE-2025-68613, and CVE-2026-3055 for current remediation guidance. Security teams should monitor for exploitation attempts targeting these vulnerabilities and apply official patches or mitigations as they become available. Given the autonomous nature of the attacks, organizations should prioritize timely vulnerability management and exposure reduction of internet-facing services. No vendor advisory content was provided indicating no action is required or that the issue is already mitigated.
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
Description
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat actor leverages DeepSeek as the reasoning engine behind Hermes Agent, an AI framework capable of executing OS commands and internet interactions autonomously. Hermes was configured to operate in a 'Yolo' mode, executing commands without operator approval, and integrated with the FOFA internet asset search engine to identify exposed servers. The agent autonomously scanned for vulnerabilities such as CVE-2026-33017 in Langflow servers and a chained exploit involving CVE-2026-21858 and CVE-2025-68613 targeting the n8n platform. Despite extensive autonomous attempts, no successful compromises were observed from these AI-driven attacks. However, manual attacks by the actor exploited vulnerabilities including CVE-2026-3055 in Citrix NetScaler, resulting in at least three confirmed compromises. The campaign highlights an AI-driven workflow capable of rapid target identification, exploit selection, and attack execution, significantly reducing the time required for manual analysis.
Potential Impact
The autonomous AI attack workflow accelerates the reconnaissance and exploitation phases of cyberattacks, enabling rapid identification and targeting of vulnerable systems. While the autonomous attacks observed did not result in successful compromises, the actor's manual attacks achieved confirmed breaches, including session hijacking via Citrix NetScaler vulnerabilities. This demonstrates the potential for AI-driven tools to enhance attacker efficiency and scale, increasing the risk of rapid exploitation of newly discovered vulnerabilities.
Defensive Guidance
Patch status is not yet confirmed — check the vendor advisories for CVE-2026-33017, CVE-2026-21858, CVE-2025-68613, and CVE-2026-3055 for current remediation guidance. Security teams should monitor for exploitation attempts targeting these vulnerabilities and apply official patches or mitigations as they become available. Given the autonomous nature of the attacks, organizations should prioritize timely vulnerability management and exposure reduction of internet-facing services. No vendor advisory content was provided indicating no action is required or that the issue is already mitigated.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/","fetched":true,"fetchedAt":"2026-07-31T19:18:41.034Z","wordCount":1038}
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a6cf512bf32cb7a3423230e
Added to database: 07/31/2026, 19:18:42 UTC
Last enriched: 07/31/2026, 19:19:11 UTC
Last updated: 09/14/2026, 21:35:30 UTC
Views: 143
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.