Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
A Chinese-speaking threat actor, tracked as ‘KnYuan’ and ‘Knaithe’, utilized the Hermes Agent framework and DeepSeek to autonomously launch attacks against over 460 targets. The agent, leveraging Telegram, identified and exploited vulnerabilities in systems running Langflow, n8n, and Marimo, resulting in data exfiltration and command execution attempts. The operation involved a complex chain of vulnerabilities, including unauthenticated file access and expression injection, and highlighted the risks associated with publicly accessible workflow interfaces and exposed SAML identity providers.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
