CVE

CVE-2026-39987

marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass

Exploitation IoCs 17

Domain api[.]deepseek[.]com
Domain cdnorigin[.]net
Domain code[.]newcli[.]com
Domain dashscope[.]aliyuncs[.]com
Filename /home/worker
Filename fofoapi.py
Filename http.server
Filename langflow_poc.py
Filename python3 -m http.server 8888
GitHub Repo Chocapikk/CVE-2026-21858
GitHub Repo Hermes Agent
GitHub Repo oscar-mine/CVE-2026-33017
GitHub Repo qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC
GitHub User KnYuan
GitHub User knaithe
SHA-1 31c69b3e12936abca770d430066f379ec1d997ec
IP 209[.]99[.]186[.]235

MITRE ATT&CK TTPs 16

Source Articles

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. These include a critical remote code execution flaw in Langflow (CVE-2026-9198), a sensitive data encryption bypass in Apache Tomcat (CVE-2026-34486), and an authentication bypass in N-able N-central (CVE-2026-18556 and CVE-2026-18577). Exploitation of CVE-2026-34486 has been linked to a Chinese-speaking threat actor using the aliases knaithe and KnYuan, who leveraged AI-powered offensive tools like DeepSeek via the Hermes Agent framework to autonomously target internet-exposed systems. The actor combined autonomous reconnaissance with manual exploitation of known vulnerabilities in Citrix NetScaler, Marimo, and IKE VPN, among others, targeting over 460 organizations.
hacker-news Aug 5, 2026
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
A Chinese-speaking threat actor using the aliases knaithe and KnYuan leveraged the open-source Hermes Agent framework, powered by DeepSeek as the primary reasoning model, to autonomously conduct cyberattacks. The actor issued initial commands via Telegram, after which the agent independently identified internet-facing systems, selected public exploits, and attempted exploitation without further input. The campaign targeted vulnerabilities in Langflow, n8n, Marimo, and Citrix NetScaler systems, with confirmed exploitation of CVE-2026-3055 and CVE-2026-39987, though only three systems were successfully compromised. The operation was exposed due to an unintentional HTTP server exposing configuration files, API keys, exploit scripts, and logs.
hacker-news Jul 31, 2026
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has launched an AI-powered autonomous hacking campaign leveraging the Hermes Agent framework with DeepSeek as a reasoning engine to exploit seven critical vulnerabilities in Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, Palo Alto PAN-OS, and Microsoft Windows IKE Extensions. The campaign uses AI models to autonomously conduct vulnerability assessment, target selection, and exploit generation, with command and control coordinated via Telegram. The actor also leverages publicly available AI tools like Claude Code, Codex, and Qwen Code to support operations. When initial exploitation fails, the system automatically searches for new critical CVEs using GitHub PoCs to prioritize attack surfaces.
hacker-news Jul 30, 2026
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 identified a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan who conducted an AI-enabled autonomous cyberattack campaign. The actor used the Hermes Agent framework with DeepSeek as the reasoning engine to autonomously enumerate vulnerabilities, acquire exploit code, and launch attacks without human intervention. They targeted multiple vulnerabilities including CVE-2026-33017 in Langflow and chained CVEs in n8n (CVE-2026-21858 and CVE-2025-68613), though exploitation attempts failed due to configuration requirements. Manual operations successfully exploited CVE-2026-3055 in Citrix NetScaler, leading to confirmed data exfiltration. The campaign was exposed when the actor accidentally exposed their infrastructure via an HTTP file server.
unit42 Jul 30, 2026
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go-based botnet named NadMesh, discovered in early July 2026, actively targets exposed AI and cloud services to harvest cloud credentials, Kubernetes tokens, and model access. The malware prioritizes exploitation of MCP (Model Context Protocol) services, Docker APIs, Jenkins consoles, and Redis instances, with a focus on credential theft rather than host compromise. The operator uses self-propagating scanning infrastructure, persistence mechanisms, and obfuscation to evade detection, while targeting specific ports associated with AI tools like ComfyUI, Ollama, Gradio, and n8n. Researchers observed real-time exploitation traffic, though success rates for MCP exploitation remain low compared to other vectors.
hacker-news Jul 17, 2026