Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hacker uses DeepSeek AI to autonomously attack vulnerable servers

0
Medium
Vulnerabilityrce
Published: 07/31/2026 (07/31/2026, 17:35:35 UTC)
Source: Bleeping Computer

Description

A Chinese-speaking threat actor is using the DeepSeek AI model combined with the open-source Hermes Agent to autonomously conduct cyberattacks on internet-exposed servers with minimal human intervention. The AI agent independently identifies vulnerable targets, researches exploits, and attempts exploitation, focusing on platforms like Langflow and n8n workflow automation. Although these autonomous attacks did not successfully compromise targets, manual attacks by the same actor achieved some success exploiting Citrix NetScaler vulnerabilities. This campaign demonstrates a functional autonomous offensive AI capability that accelerates reconnaissance and exploitation processes.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 19:19:11 UTC

Technical Analysis

The threat actor leverages DeepSeek as the reasoning engine behind Hermes Agent, an AI framework capable of executing OS commands and internet interactions autonomously. Hermes was configured to operate in a 'Yolo' mode, executing commands without operator approval, and integrated with the FOFA internet asset search engine to identify exposed servers. The agent autonomously scanned for vulnerabilities such as CVE-2026-33017 in Langflow servers and a chained exploit involving CVE-2026-21858 and CVE-2025-68613 targeting the n8n platform. Despite extensive autonomous attempts, no successful compromises were observed from these AI-driven attacks. However, manual attacks by the actor exploited vulnerabilities including CVE-2026-3055 in Citrix NetScaler, resulting in at least three confirmed compromises. The campaign highlights an AI-driven workflow capable of rapid target identification, exploit selection, and attack execution, significantly reducing the time required for manual analysis.

Potential Impact

The autonomous AI attack workflow accelerates the reconnaissance and exploitation phases of cyberattacks, enabling rapid identification and targeting of vulnerable systems. While the autonomous attacks observed did not result in successful compromises, the actor's manual attacks achieved confirmed breaches, including session hijacking via Citrix NetScaler vulnerabilities. This demonstrates the potential for AI-driven tools to enhance attacker efficiency and scale, increasing the risk of rapid exploitation of newly discovered vulnerabilities.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisories for CVE-2026-33017, CVE-2026-21858, CVE-2025-68613, and CVE-2026-3055 for current remediation guidance. Security teams should monitor for exploitation attempts targeting these vulnerabilities and apply official patches or mitigations as they become available. Given the autonomous nature of the attacks, organizations should prioritize timely vulnerability management and exposure reduction of internet-facing services. No vendor advisory content was provided indicating no action is required or that the issue is already mitigated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/","fetched":true,"fetchedAt":"2026-07-31T19:18:41.034Z","wordCount":1038}

Threat ID: 6a6cf512bf32cb7a3423230e

Added to database: 07/31/2026, 19:18:42 UTC

Last enriched: 07/31/2026, 19:19:11 UTC

Last updated: 07/31/2026, 19:36:41 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses