Palo Alto Networks' threat intelligence unit Unit 42 has documented what it describes as a functional, end to end autonomous offensive capability powered by an AI model. In a campaign attributed to a Chinese speaking actor operating under the aliases "knaithe" and "KnYuan" assessed by researchers to be based in Zhuhai, China DeepSeek was wired into the open source Hermes Agent framework to serve as an autonomous offensive operator.
According to the report, the workflow required the human operator to send a single Telegram instruction and then largely step back. Unit 42 recovered a complete session from May 2026 in which no additional operator input was found after the initial task: DeepSeek handled target enumeration, vulnerability selection, exploit sourcing from GitHub, and attack execution on its own. The actor launched exploitation attempts against more than 460 targets using both autonomous and conventional workflows.
Notably, the actor did not begin with DeepSeek. Unit 42's report indicates the operator first approached Western AI models and that both Claude and OpenAI refused the offensive tasks. OpenAI reportedly went further, and its safety systems independently detected and disabled an account linked to the campaign before Unit 42 shared its intelligence. DeepSeek, however, did not refuse, which likely led the actor to select the most permissive model for the operation.
Unit 42 concluded that version 1.121.1 is the earliest n8n release addressing both flaws used in the attempted chain, and that Marimo fixed CVE-2026-39987 in version 0.23.0.
The autonomous DeepSeek campaigns failed against targets with stronger default configurations. The operator's manual operations did not. Unit 42's report separately describes data exfiltration from three organizations and command execution on eleven Marimo instances. Researchers have not yet publicly reconciled these figures with the limited impact of the autonomous attacks.
One of the most unusual aspects of the case is how the operation was uncovered: Hermes Agent inadvertently launched python3 -m http.server 8888 from /home/worker, making the operator's model configurations, API keys, exploit scripts, target lists, shell history, and autonomous session logs publicly accessible. This accidental exposure gave Unit 42 investigators a rare, in depth view of the entire operation.
| System | Action |
|---|---|
| Langflow, n8n, Marimo | Patch exposed instances; update n8n to ≥ 1.121.1 and Marimo to ≥ 0.23.0. |
| Citrix NetScaler ADC / Gateway | Patch customer managed appliances configured as SAML identity providers (CVE-2026-3055). |
| Workflow & notebook interfaces | Remove unnecessary public access; enforce authentication on all exposed endpoints. |
Unit 42 warned that targets with weaker default configurations would have been susceptible, and emphasized that in this documented case, no detection fired and no alert was raised the AI campaign was only stopped by authentication configuration, not by monitoring.
Security researchers describe the incident as one of the most prominent examples to date of large language models being used as autonomous attack tools that can operate without constant human supervision. It also highlights a legal and geopolitical dimension: because data submitted to DeepSeek's API may be subject to Chinese government access on demand, organizations evaluating DeepSeek for their own deployments face a fixed condition based on the model's jurisdiction of origin.