unit42.paloaltonetworks.com 7/30/2026, 10:32:04 AM · external

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Developing story campaign 3 articles tracked
Langflow RCE flaw (CVE-2026-33017) exploited to deploy Monero cryptominer
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

UNIT 42 has uncovered an AI-driven autonomous hacking campaign by a Chinese-speaking actor who utilized AI models for cyberattacks. The actor used various tools, including the DeepSeek framework operating via the Hermes Agent, to target infrastructure vulnerabilities, autonomously enumerating targets and sourcing exploit tools. Key findings include:

Notable identified CVEs included CVE-2026-33017 (Langflow) and a combination exploit targeting n8n (CVE-2026-21858 and CVE-2025-68613). The report emphasizes the emerging threat of AI-enabled attacks and the need for organizations to enhance protective measures using products like Cortex XDR, Cortex XSIAM, and Next-Generation Firewall.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline