Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Summary
A Chinese-speaking hacker used DeepSeek (an AI model) through the Hermes Agent framework (a tool that lets AI systems run autonomous tasks) to launch automated cyberattacks against over 460 targets after sending a single Telegram command. The AI independently searched for vulnerable systems, selected exploits (pre-made attack code), and attempted to compromise multiple products including Langflow, n8n, and Marimo, though most attacks failed because target systems didn't match the exploits' requirements.
Solution / Mitigation
Organizations should patch exposed systems: Langflow to version 1.9.0 or later (fixes CVE-2026-33017), n8n to version 1.121.1 or later (fixes both CVE-2026-21858 and CVE-2025-68613), Marimo to version 0.23.0 or later (fixes CVE-2026-39987), and customer-managed NetScaler ADC or Gateway appliances configured as SAML (Security Assertion Markup Language, a system for managing user login) identity providers. Additionally, remove unnecessary public access to workflow and notebook interfaces.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html
First tracked: July 31, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 85%