
Table of Contents
Key Takeaway
- Unit 42 has documented knaithe, a Chinese-speaking developer from Zhuhai who ran a hacking operation where the DeepSeek model, driven through the Hermes Agent framework, enumerated targets, sourced exploits, and launched attacks by itself over Telegram.
- The knaithe agent surveyed 10 product families, scored CVEs by exploitability, and picked its own targets — 460 total systems probed. It failed autonomously at Langflow (CVE-2026-33017, CVSS 9.8) and n8n (CVE-2026-21858 / CVE-2025-68613, CVSS 10.0 / 9.9) only because of target-side settings.
- The confirmed damage came from the manual lane: data exfiltration from three Citrix NetScaler targets (CVE-2026-3055), including a Malaysian government entity hit persistently across multiple days, plus command execution on 11 Marimo notebook instances (CVE-2026-39987).
- The operation blew its own cover when the agent started a file server in the home directory — exposing AI tool configs, API keys, exploit scripts, and session logs to researchers.
- For Filipino teams, the lesson is not “AI attacks are coming.” They are here, they fail on configuration hygiene, and the same open-source agent frameworks Filipino devs use daily are the ones wired into this attack chain.
Here is the sentence that should reorganize how you think about attackers this year: a threat actor told an AI what to do once, and the AI spent the campaign hunting targets by itself. Palo Alto Networks’ Unit 42 published the full anatomy of this operation on Tuesday. The actor’s aliases are knaithe and KnYuan. The engine of the knaithe operation was DeepSeek, wired for offense through the Hermes Agent framework, controlled from Telegram.
And one more detail that should sting for every developer reading this: the framework in the middle of this attack chain is open source, free, and sits in the same category as the agent frameworks Filipino teams deploy every day to automate their own workflows. The lesson of the knaithe file is not that some exotic military AI exists. The knaithe operation proves something smaller and worse: a self-described binary security researcher assembled a working autonomous attack shop out of parts you can download this afternoon.
Who knaithe Is — and What the knaithe Agent Actually Did
Unit 42 identifies the actor as a Chinese-speaking developer based in Zhuhai, an opportunistic exploit operator and self-described binary security researcher. He maintains 1DayNews, an automated vulnerability intelligence pipeline that aggregates RCE disclosures from 17 sources, uses DeepSeek to filter for exploitability, and pushes alerts to Telegram. That pipeline is the reconnaissance backbone of this story — same model, same messaging channel, same operator.
The knaithe campaign split into two lanes. In the autonomous lane, the DeepSeek hacking agent enumerated targets on FOFA, downloaded public exploit code from GitHub, and attempted intrusions without human intervention. In the manual lane, the actor ran conventional workflows — custom Python scanners, direct exploitation — that produced the confirmed impacts. Both lanes fed from the same CVE watchlist.
The numbers tell you what “autonomous” actually means at this scale: the actor attempted to exploit more than 460 targets. The AI lane surveyed ten product families via FOFA, scanned GitHub for trending 2026 CVE proofs of concept sorted by stars, evaluated each candidate by severity, deployment footprint, and exploitability, then picked its own targets. Unit 42’s verdict on that behavior: the system executed hundreds of hours of manual targeting analysis in mere minutes, while managing its own compute budget — it sampled roughly 100 of 25,209 Chinese n8n instances to keep costs down.

The Attack Log, Phase by Phase
Unit 42 recovered a complete session from May 7, 2026 — with the operator’s input visible only at the very start. Everything after that is the agent working alone.
Phase 1 — Langflow, failed. The DeepSeek hacking agent identified CVE-2026-33017 (CVSS 9.8) in Langflow, downloaded a public proof of concept from GitHub, enumerated 84 Langflow instances on FOFA, and ran a 10-thread scanner to find vulnerable versions. It found one, Langflow 1.3.4 — and the exploit required auto_login or a public flow ID, which the target had neither of. The agent’s own assessment, recovered from the session log: “All three Langflow need public flow ID but no auto_login — stuck. Deployments small (84 alive), exploitable probably 0. Search for larger-scale vulns.” The AI ranked its own target as a dead end and moved on.
Phase 2 — CVE research, autonomous. The knaithe agent surveyed deployment counts across 10 product families, then searched GitHub for trending 2026 CVE PoC repositories sorted by stars — the NVD records later confirmed its version math. Its pick: n8n, on the reasoning — quote — “The n8n one with 258 stars and CVSS 10.0 looks extremely promising.” FOFA confirmed 647,017 n8n instances globally, 25,209 of them in China. An AI chose its own next battlefield by reading star counts on exploit repos. Sit with that for a second.
Phase 3 — exploit acquisition and version triage. The agent pulled public exploit code from the Chocapikk repository, chaining CVE-2026-21858 (arbitrary file read, CVSS 10.0, patched in n8n 1.121.0) with CVE-2025-68613 (sandbox bypass to remote code execution, CVSS 9.9, patched in 1.120.4). It then version-triaged targets on its own: “So v1.117.3 is vulnerable to both!”
Phase 4 — enumeration and the wall. The knaithe agent probed Chinese n8n instances for version and form endpoints, confirmed three running vulnerable versions (v1.18.0, v1.117.3, v1.108.2), then hit the same wall as Langflow: the exploit needs an unauthenticated form with file upload, and every form it found required authentication. The agent noticed, re-read the exploit code, launched parallel scans across 50-plus remaining targets, found nothing public, and quit. No exploitation. The session log ends there.
Read those four phases again and notice what is missing: no human decisions between them. The agent picked the CVEs, picked the targets, sourced the code, scanned, failed, self-assessed, pivoted, and gave up — a full kill chain of decisions made by a model reading its own tool outputs.
The Manual Lane Did the Real Damage
Where the knaithe agent failed, the human hands succeeded. Unit 42 confirmed four manual operations with real impact:
- Data exfiltration from three organizations via Citrix NetScaler (CVE-2026-3055, CVSS 9.8). The actor pulled memory data through the out-of-bounds read, then searched it for NetScaler authentication cookies (NSC_AAAC=) — session-hijacking prep on real infrastructure.
- Command execution on 11 Marimo notebook instances (CVE-2026-39987, CVSS 9.8).
- Java deserialization reverse-shell attempts against nine Apache Tomcat servers (CVE-2026-34486).
- Reverse-shell callbacks against three Windows IKE VPN endpoints (CVE-2026-33824).
The most deliberate targeting was a government entity in Malaysia. The actor exploited it persistently across multiple days, refining memory-grooming parameters and retrying with maximum read attempts, and switched to proxy anonymization on later attempts. One government, hunted with patience, by a human — while the agent worked the opportunistic lane.
The seventh CVE on the workbench, CVE-2026-0300, a buffer overflow in the PAN-OS User-ID Authentication Portal, was cloned from a public repository but contained placeholder values and was never executed. That tells you the tooling bench matters more than any single exploit: seven CVEs kept loaded on the shelf, four with confirmed or attempted use, one autonomous engine cycling through the list.

How the Operation Exposed Itself
The break in the knaithe case is almost comic. The Hermes Agent, responding to a Telegram command, started an HTTP file server — python3 -m http.server 8888 — from the actor’s home directory instead of an isolated staging directory. That single command exposed the entire workspace: AI tool configurations, API keys, exploit scripts, target lists, bash history, and the autonomous exploitation session logs that gave Unit 42 the phase-by-phase record above.
The irony stacks up. The actor emptied exploit directories after use and disabled Codex conversation logging — real operational security discipline. But the AI operator he built to save time was the component that burned him, because it ran a command from the wrong directory. Unit 42 notes the exposure was unintentional. His own automation violated his own security posture. Filipino teams automating their own ops with agents should read that twice, because the same class of mistake — an agent writing outside its lane — ends in the same place whether your agent is benign or not. The DIVD kill-chain file is the same lesson: agent infrastructure is attack infrastructure.
The Tool Bench: How the Actor Wired His AI Stack
Unit 42 recovered the complete knaithe configuration table, and it reads like a market survey:
- DeepSeek via Hermes Agent — the primary offensive pair: framework with no built-in safety layer, custom red-team skills including a “godmode” LLM-jailbreaking skill, direct API access to api.deepseek.com.
- Claude Code (Opus, via proxy) — used only for connectivity testing and proxy validation: 10 session entries across three sessions, all model checks and connectivity tests. Configured with dangerously-skip-permissions enabled and 12 tools allowlisted, routed through a third-party proxy to hide attribution.
- Codex (GPT-5.4, via proxy) — signs of use in exploit-development directories, chat logs unrecovered because the actor set disable_response_storage to true. OpenAI confirmed to Unit 42 that its safeguards refused policy-violating requests and flagged an account linked to this campaign for disablement before Unit 42’s outreach.
- Qwen Code (GLM-5/Qwen/Kimi/MiniMax) — two sessions total, direct API access, approvalMode set to fully autonomous.
The pattern is the market evaluation every developer knows: try several tools, keep the one that works. The actor’s criterion was permissiveness. His own quote trail shows Western provider-side controls limiting autonomous attack usefulness — Claude refusing to escalate, Codex refusing policy violations — which is exactly why he standardized on DeepSeek behind a framework with no client-side restrictions. The threat model for Filipino developers is not “your AI will turn evil.” It is “an attacker is grading every model on the market for the same license-to-operate you are, and picking the one that says yes.”

What This Means for Filipino Teams
Three concrete readings of the knaithe file for a Philippine security team — and knaithe’s own failures are the syllabus:
1. Configuration hygiene stopped everything — not security products. The knaithe autonomous lane failed on auto_login settings (Langflow), authenticated forms (n8n), and nothing else. Both products are in daily use in PH tech: n8n in particular has become the default glue for local startups automating marketing and ops — our own newsroom runs on an n8n workflow. If a deployment exposes an unauthenticated form endpoint, the recovered play — a CVSS 10.0 file-read chained into a 9.9 sandbox escape downloaded from a public repo — runs against it without modification. Inventory your n8n and Langflow deployments tonight, and confirm every form endpoint requires authentication.
Patch n8n to 1.121.0 or later for the file-read fix, 1.120.4 or later for the sandbox escape fix.
2. The edge devices knaithe’s manual lane loved are the same ones PH infrastructure runs. Citrix NetScaler appliances (session hijacking via cookie theft), Windows IKE VPN endpoints, Apache Tomcat servers — this is the standard perimeter of a mid-size Philippine enterprise, a BPO network, or an LGU data center. The victim list proves the playbook transfers: data memory-reads on NetScaler, reverse shells on Tomcat and IKE. CVE-2026-3055 deserves its own patch verification this week — the exfiltrated memory was searched for session cookies, which is a stolen-login pipeline, not just an information disclosure.
3. Expect the next knaithe campaign not to fail. Unit 42’s own conclusion: the margin of failure was narrow, and targets with weaker default configurations would have been susceptible. That sentence is the entire threat model for 2026. The agent did everything right up to the last configuration check, and it will get faster at that too — the same autonomous cycle that surveyed 10 product families in minutes will re-run next month against a target that skipped one setting. The window Defender teams have is the time between “AI attacks are viable” and “AI attacks are reliable,” and that window is closing on evidence, not speculation.
The breach chain this campaign belongs to is wider than one actor. Our third-party autopsy of the Bitget $387.5M theft, the Zammad disclosure fight, and the GitLab AI Gateway 9.9 complete the picture — four stories, one lesson: the AI layer is the new perimeter.
The Defenders’ Checklist
For a PH team that wants to check itself against this exact campaign this week:
- Patch the three names in the attack log. n8n to 1.121.0+ (file read) and 1.120.4+ (sandbox RCE). Langflow if you run it — CVE-2026-33017. Citrix NetScaler CVE-2026-3055 if you run appliances. Marimo notebooks CVE-2026-39987 if any team member uses them.
- Kill unauthenticated form endpoints on n8n/Langflow deployments tonight. This one setting decided both autonomous campaigns.
- Search appliance memory access logs for anomalous read volumes on NetScaler — the exfil signatures were out-of-bounds reads with memory-grooming parameters, retried with maximum attempts over days.
- Hunt for the agent’s fingerprints: HTTP file servers running from home directories (python3 -m http.server on port 8888 in this case), unusual FOFA-scanner patterns against your internet-facing assets, and outbound connections to api.deepseek.com from servers that have no business calling an LLM API.
- Assume the automation platform is an attack surface. The same logic we wrote about the GitLab AI Gateway flaw applies one story later — AI infrastructure is the new edge, and the glue tools connecting everything are the entry points.
Frequently Asked Questions
What is the knaithe campaign?
The knaithe campaign: an autonomous hacking operation documented by Palo Alto Networks’ Unit 42 in which a Chinese-speaking developer in Zhuhai used the DeepSeek model through the Hermes Agent framework, commanded over Telegram, to enumerate targets on FOFA, download public exploit code from GitHub, and attempt intrusions without human intervention — while parallel manual operations produced confirmed data theft from Citrix NetScaler targets and command execution on Marimo notebooks.
Did the DeepSeek hacking agent succeed?
The autonomous lane did not achieve confirmed exploitation — it failed at Langflow because auto_login was disabled and at n8n because form endpoints required authentication. The confirmed impacts came from the actor’s manual lane: memory-data exfiltration from three Citrix NetScaler targets (CVE-2026-3055) and command execution on 11 Marimo notebook instances (CVE-2026-39987), plus a persistently exploited government entity in Malaysia.
Which CVEs were used?
Seven CVEs sat on the actor’s shelf: CVE-2026-33017 (Langflow, 9.8, autonomous attempt failed), CVE-2026-21858 (n8n, 10.0) and CVE-2025-68613 (n8n, 9.9, autonomous attempt failed), CVE-2026-3055 (Citrix NetScaler, 9.8, exploited — data exfiltrated), CVE-2026-39987 (Marimo, 9.8, exploited — command execution), CVE-2026-34486 (Apache Tomcat, 7.5, manual attempts), CVE-2026-33824 (Windows IKE, 9.8, manual attempts), and CVE-2026-0300 (PAN-OS, 9.8, cloned but non-functional and never executed).
Can DeepSeek be used for hacking?
In this campaign it was. DeepSeek served as the reasoning engine inside the Hermes Agent framework — Unit 42 notes the framework has no built-in safety layer and carried custom red-team skills including a jailbreaking skill. Western tools (Claude Code, Codex) were tested but their provider-side safeguards limited autonomous attack usefulness; OpenAI flagged and disabled an account linked to the campaign. The differentiator was permissiveness, not capability.
Should Philippine teams be worried about AI-driven attacks?
Treat this as a configuration-hygiene problem first. Every autonomous attempt in this campaign failed on a target-side setting, not a security product. If your n8n or Langflow deployment exposes an unauthenticated form endpoint, the recovered autonomous play runs against it unmodified. Patch, kill unauthenticated endpoints, and inventory the agent frameworks in your own stack — the framework at the center of this operation is open source and free.





