A hacker let AI run his cyberattacks solo. It barely worked — and that's the scary part

A DeepSeek-powered agent tried to hack 460+ systems on its own, including a Windows VPN bug rated CVSS 9.8 — and got shut out everywhere…

Aliteq
Priya Nair · Software & Systems Editor

The short version

A Chinese-speaking threat actor (aliases knaithe / KnYuan) ran a Telegram-orchestrated AI framework, Hermes Agent, powered by DeepSeek, to autonomously find and fire exploits at internet-facing…

The short version

The AI-only phase targeted 7 CVEs across 460+ systems and confirmed zero compromises — basic authentication and default settings stopped it every time.

The short version

The same operator's manual follow-up succeeded: 3 Citrix NetScaler instances had data exfiltrated, 11 Marimo Notebook instances got remote code execution.

The short version

One target was CVE-2026-33824, a CVSS 9.8 double-free in Windows' IKE VPN service — patched in this month's Patch Tuesday, with confirmed reverse-shell attempts already logged against it.

The short version

Unit 42 calls the operation "functionally autonomous" but says its real-world hit rate still trails a skilled human operator by a wide margin.

My take

I think the "AI hacked X" framing overstates where this actually is. An agent that can chain public exploit tools together isn't the same thing as one that can adapt when it hits a login wall — and…

Aliteq

Read the full story

A hacker let AI run his cyberattacks solo. It barely worked — and that's the scary part

Read the full story on Aliteq