CVE
CVE-2026-21858
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
Exploitation IoCs 13
Domain api[.]deepseek[.]com
Domain code[.]newcli[.]com
Domain dashscope[.]aliyuncs[.]com
Filename /home/worker
Filename fofoapi.py
Filename http.server
Filename langflow_poc.py
Filename python3 -m http.server 8888
GitHub Repo Chocapikk/CVE-2026-21858
GitHub Repo oscar-mine/CVE-2026-33017
GitHub Repo qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC
GitHub User KnYuan
GitHub User knaithe
MITRE ATT&CK TTPs 21
T1021 T1046 T1059 T1059.001 T1071.001 T1078 T1082 T1090 T1133 T1190 T1203 T1210 T1485 T1566 T1583 T1584 T1585 T1586 T1587 T1588 T1588.001
Remote Services
Lateral Movement
Network Service Discovery
Discovery
Command and Scripting Interpreter
Execution
PowerShell
Execution
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
Proxy
Command And Control
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Exploitation of Remote Services
Lateral Movement
Data Destruction
Impact
Phishing
Initial Access
Acquire Infrastructure
Resource Development
Compromise Infrastructure
Resource Development
Establish Accounts
Resource Development
Compromise Accounts
Resource Development
Develop Capabilities
Resource Development
Obtain Capabilities
Resource Development
Malware
Resource Development
Source Articles
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A China-based threat actor using the aliases 'knaithe' and 'KnYuan' has leveraged the DeepSeek AI model in conjunction with the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with minimal human intervention. The attacker configured Hermes to use DeepSeek as a reasoning engine, enabling it to autonomously discover vulnerabilities, select targets, download exploit code, and attempt exploitation — including targeting Langflow servers via CVE-2026-33017 and n8n instances using chained exploits CVE-2026-21858 and CVE-2025-68613. While the autonomous attacks failed to successfully compromise systems due to authentication requirements, the actor manually exploited CVE-2026-3055 in Citrix NetScaler to achieve three successful compromises, extracting memory and hunting for session cookies. This campaign demonstrates a functional end-to-end autonomous offensive capability that dramatically accelerates the attack lifecycle.
bleeping-computer Jul 31, 2026
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
A Chinese-speaking threat actor using the aliases knaithe and KnYuan leveraged the open-source Hermes Agent framework, powered by DeepSeek as the primary reasoning model, to autonomously conduct cyberattacks. The actor issued initial commands via Telegram, after which the agent independently identified internet-facing systems, selected public exploits, and attempted exploitation without further input. The campaign targeted vulnerabilities in Langflow, n8n, Marimo, and Citrix NetScaler systems, with confirmed exploitation of CVE-2026-3055 and CVE-2026-39987, though only three systems were successfully compromised. The operation was exposed due to an unintentional HTTP server exposing configuration files, API keys, exploit scripts, and logs.
hacker-news Jul 31, 2026
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has launched an AI-powered autonomous hacking campaign leveraging the Hermes Agent framework with DeepSeek as a reasoning engine to exploit seven critical vulnerabilities in Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, Palo Alto PAN-OS, and Microsoft Windows IKE Extensions. The campaign uses AI models to autonomously conduct vulnerability assessment, target selection, and exploit generation, with command and control coordinated via Telegram. The actor also leverages publicly available AI tools like Claude Code, Codex, and Qwen Code to support operations. When initial exploitation fails, the system automatically searches for new critical CVEs using GitHub PoCs to prioritize attack surfaces.
hacker-news Jul 30, 2026
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 identified a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan who conducted an AI-enabled autonomous cyberattack campaign. The actor used the Hermes Agent framework with DeepSeek as the reasoning engine to autonomously enumerate vulnerabilities, acquire exploit code, and launch attacks without human intervention. They targeted multiple vulnerabilities including CVE-2026-33017 in Langflow and chained CVEs in n8n (CVE-2026-21858 and CVE-2025-68613), though exploitation attempts failed due to configuration requirements. Manual operations successfully exploited CVE-2026-3055 in Citrix NetScaler, leading to confirmed data exfiltration. The campaign was exposed when the actor accidentally exposed their infrastructure via an HTTP file server.
unit42 Jul 30, 2026