HomeArtificial Intelligence (AI)A Hacker's Own Mistake Just Proved AI Can Run a Cyberattack With...

A Hacker’s Own Mistake Just Proved AI Can Run a Cyberattack With Almost No Human Help

Palo Alto Networks’ Unit 42 published a report on July 30, 2026 documenting the first fully observed case of an AI model independently running an offensive cyberattack cycle — enumerating targets, selecting vulnerabilities, sourcing exploit code, and executing attacks with minimal human input. Researchers only found it because the attacker’s own AI agent made a configuration mistake that exposed the entire operation.

The threat actor, tracked under the aliases “knaithe” and “KnYuan” and assessed to be based in Zhuhai, China, wired DeepSeek’s model into Hermes Agent, an open-source agentic framework, giving it terminal access and orchestration capability. The operator issued a single command over Telegram, then largely stepped back — Unit 42 recovered a complete session from May 2026 in which no further operator input was found after that initial instruction. DeepSeek independently ran FOFA-based target enumeration, evaluated CVEs, sourced exploit code from GitHub, and adapted its attack logic across the session, according to Unit 42’s own published report.

The mistake that exposed everything

Hermes Agent accidentally launched an HTTP file server from the operator’s home directory instead of a sandboxed staging location — a basic misconfiguration that made the attacker’s exploit scripts, target lists, API keys, session logs, and command history publicly accessible. That accident gave defenders a rare, complete view into a live AI-driven offensive operation, rather than the usual fragmentary evidence security teams piece together after the fact.

Where the autonomous attacks actually worked — and where they didn’t

The DeepSeek-led autonomous campaigns against Langflow and n8n systems failed, because the exposed targets didn’t match the exploits’ configuration requirements. The operator’s separate, manually run campaigns had real impact: Unit 42 confirmed data exfiltration from three organizations through a Citrix NetScaler memory-overread flaw (CVE-2026-3055) and command execution on 11 Marimo notebook instances via a second vulnerability. Notably, the report indicates the operator tried Claude Code and OpenAI’s Codex during the campaign but relied on them only for narrow, low-risk tasks like connectivity testing — consistent with those platforms’ safety controls blocking more direct offensive use, while DeepSeek did not.

Why this matters beyond one operator

Unit 42’s core finding isn’t the specific CVEs exploited — it’s that a functional, largely autonomous scan-research-exploit pipeline is now demonstrably achievable with off-the-shelf open-source tooling and a commercially available AI model. The actor also tested Qwen, GLM, Kimi, and MiniMax in parallel, suggesting an active, ongoing evaluation of which AI models offer the least resistance to offensive use — a shopping process defenders should assume other threat actors are running too.

Unit 42’s report leaves one detail unresolved: it states the operator attempted exploitation against roughly 460 targets across seven distinct exploit paths, yet confirms only three targets were successfully compromised, without fully reconciling that gap in scale. Researchers have said they’ve contacted Palo Alto Networks for clarification. Whatever the precise success rate, the operational template itself — a single Telegram command triggering a largely unsupervised scan-and-exploit cycle — is the part defenders can’t unsee.

What to watch next

  • Whether DeepSeek or other Chinese AI labs adjust safety controls in response to this documented misuse.
  • Whether other threat actors replicate the same DeepSeek-plus-Hermes-Agent stack now that a working blueprint has been publicly analyzed.
  • Whether the disclosed CVEs, including the Citrix NetScaler flaw, see a wave of copycat exploitation now that technical details are public.

Sources


Disclaimer: This content is meant to inform and should not be considered financial advice. The views expressed in this article may include the author’s personal opinions and do not represent Times Tabloid’s opinion. Readers are advised to conduct thorough research before making any investment decisions. Any action taken by the reader is strictly at their own risk. Times Tabloid is not responsible for any financial losses.

Solomon Odunayo
Solomon Odunayo
Solomon is a trader, crypto enthusiast, and analyst with over seven years of experience in the industry. He strongly believes that crypto assets and the blockchain will continue to gain prominence. At TimesTabloid.com, he focuses on news, articles with deep analysis of blockchain projects, and technical analysis of crypto trading pairs.
RELATED ARTICLES

Latest News & Articles