Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks — Swati KhandelwalJul 31, 2026Artificial Intelligence / Cyber Attack [https://blo

chinese-hacker-commands-deepseek-via-telegram-to-launch-autonomous-attacks

What’s new: A Chinese-speaking threat actor utilized the open-source Hermes Agent framework to command an AI model named DeepSeek for autonomous cyberattacks. The actor launched exploitation attempts against over 460 targets, focusing on vulnerabilities in Langflow, n8n, and Marimo systems. However, most attempts were unsuccessful due to configuration issues. The operation also involved data exfiltration from three organizations using specific vulnerabilities, with only three successful exploits confirmed. The Hermes Agent inadvertently exposed sensitive operational data through an unintended HTTP server.

Who’s affected

Organizations using Langflow, n8n, and Marimo systems, as well as customer-managed Citrix NetScaler ADC and Gateway appliances configured as SAML identity providers, are at risk.

What to do

  • Patch exposed Langflow, n8n, and Marimo systems to the latest versions: Langflow (1.9.0), n8n (1.121.1), and Marimo (0.23.0).
  • Check Citrix NetScaler configurations for vulnerabilities related to CVE-2026-3055 and apply the necessary updates.
  • Remove unnecessary public access to workflow and notebook interfaces.

Sources