Chinese hacker knaithe used DeepSeek AI agent to breach over 460 targets, exploited flaws now in CISA KEV catalog
A Chinese-speaking hacker known as knaithe used DeepSeek via an autonomous AI agent to scan and exploit internet-exposed systems, hitting over 460 targets, per Palo Alto Networks $PANW Unit 42. CISA added three exploited flaws to its KEV catalog Wednesday. Agencies must patch by
A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan, based in Zhuhai, China, used the AI model DeepSeek through an autonomous agent framework called Hermes to scan for and exploit vulnerable, internet-exposed systems, according to Palo Alto Networks $PANW Unit 42. When an initial attempt to exploit a Langflow vulnerability failed because of the target's restrictive configuration, the AI agent independently researched alternative vulnerabilities, including flaws in the automation tool n8n, to find another way in. Unit 42 says the actor combined this autonomous process with manual exploitation of known vulnerabilities in Citrix NetScaler, the Marimo notebook tool, Apache Tomcat, and IKE VPN endpoints, attempting to breach more than 460 targets in total. The U.S. Cybersecurity and Infrastructure Security Agency added three of the exploited vulnerabilities, in Langflow, Apache Tomcat, and N-able $NABL N-central, to its Known Exploited Vulnerabilities catalog on August 5. Federal civilian executive branch agencies have until August 7 to apply fixes. Unit 42 noted that the AI agent narrowed its own targeting scope to conserve compute, compressing what would normally be hundreds of hours of manual analysis into minutes. That shift, from human operators running exploit chains to an AI system doing its own reconnaissance and vulnerability triage, marks a change in how quickly attackers can move from initial access attempt to a working exploit against a new target.