< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-31T16:51:27+05:30

Chinese Threat Actor Utilizes DeepSeek and Hermes Agent for Autonomous Cyber Attacks via Telegram

A Chinese-speaking threat actor leveraged DeepSeek via the Hermes Agent framework to autonomously execute cyber attacks through Telegram, targeting multiple vulnerabilities with limited success. The attack involved exploit chains against systems like Langflow, n8n, and Marimo, highlighting the need for urgent patching and reduced public exposure of critical infrastructure.

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.

After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session.

The operator, tracked through the aliases knaithe and KnYuan,

Read original article

*** END OF TRANSMISSION ***