PALO Alto Networks Unit 42 reported on an AI-enabled autonomous cyberattack campaign run by a Chinese-speaking operator, known by the aliases knaithe and KnYuan. The campaign targeted over 460 entities, including systems in China and a Malaysian government agency, resulting in three confirmed breaches. The attacker leveraged models like DeepSeek and Hermes Agent to conduct attacks autonomously, though many attempts failed. Key vulnerabilities exploited included those found in Citrix NetScaler and Langflow.
Researchers highlighted the campaign's use of AI as a significant concern for cybersecurity, emphasizing the need for robust defensive measures against such rapidly evolving threats.