Threat actor uses DeepSeek AI and open-source Hermes Agent to autonomously attack servers
The agent found 84 exposed Langflow servers and more than 647,000 exposed n8n instances and chained several CVEs, though most authentication-dependent exploitation attempts failed.
- Security & misuse
- Notable
Palo Alto Networks’ Unit 42 reported a campaign in which a threat actor used DeepSeek as a reasoning engine paired with the open-source Hermes Agent framework to find and exploit vulnerable internet-facing servers with minimal ongoing human direction. Researchers recovered a Telegram channel used to issue instructions, and said a single high-level task was enough to set the agent scanning for targets on its own: it used the FOFA internet-asset search engine to identify 84 exposed Langflow instances and more than 647,000 exposed n8n workflow-automation instances, then chained several CVEs against Langflow and n8n, and separately exploited a Citrix NetScaler vulnerability to compromise three servers.
Unit 42 said the agent “independently researched vulnerabilities, determined which targets were the best option, downloaded exploit code” and carried out the analysis largely without further human input once tasked, completing in minutes work the firm said would normally take many hours of manual effort. The campaign was not uniformly successful: researchers logged more than 460 further exploitation attempts that failed, largely where the target required authentication the agent could not obtain.
The incident differed from an earlier case that month, in which the same Hermes framework had automated post-exploitation steps against Thailand’s Ministry of Finance after a human operator supplied the initial target and access; here the agent handled target selection and exploitation itself. Both relied on the same openly available agent framework rather than a frontier lab’s model, underscoring that autonomous-attack capability was no longer gated by access to closed frontier systems.