Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks
ID: bf3952c1-be52-57f7-8af7-b091018a0e28
STIX ID: report--bf3952c1-be52-57f7-8af7-b091018a0e28
Feed Name: GBHackers
A Chinese-speaking threat actor combined DeepSeek (an AI reasoning engine) with the Hermes Agent framework to automate reconnaissance, vulnerability research, exploit acquisition, and attack attempts against internet-facing systems; researchers observed the agent autonomously discover, prioritize, and attempt exploitation of high-severity CVEs (including Langflow, n8n) and Unit 42 attributed separate manual successful exfiltration and command execution via Citrix NetScaler and Marimo notebook vulnerabilities, underscoring the rising risk of agentic AI in offensive operations and the need for rapid patching and monitoring of exposed services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
