Chinese Threat Actor Uses AI to Run Autonomous Cyberattacks on Exposed Services
Palo Alto Networks' Unit 42 reported on July 30, 2026, that a Chinese-speaking threat group called knaithe/KnYuan deployed an autonomous attack platform combining the Hermes Agent and DeepSeek AI model. Operated via Telegram, the system independently performed reconnaissance using FOFA, downloaded proof-of-concept exploits from GitHub, evaluated attack conditions, and switched targets when initial attempts failed. The campaign targeted publicly exposed services including Langflow, n8n, Citrix NetScaler, Marimo, Apache Tomcat, and Windows IKE, exploiting multiple CVEs across these products. While fully autonomous attacks on Langflow and n8n failed due to unmet configuration prerequisites, a manual phase confirmed data exfiltration from three NetScaler devices and command execution on 11 Marimo instances. Security researchers warn that AI-driven attack platforms can compress reconnaissance and exploitation timelines significantly, requiring defenders to prioritize patching, egress filtering, and attack surface reduction.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in