Unit 42 examines autonomous cyberattacks using DeepSeek and Hermes

An autonomous FOFA-to-PoC loop is already operational in the wild โ and still brittle. Palo Alto Networks Unit 42 published a July 30 report on a Chinese-speaking operator who used DeepSeek through open-source Hermes Agent to enumerate FOFA targets, pull public PoCs, and attempt exploits without a human in the loop.
Observed autonomous runs failed on authentication and configuration gates. Separate manual campaigns by the same actor produced the confirmed damage.
How Hermes Agent drove the FOFA loop
Unit 42 attributes the activity to aliases knaithe / KnYuan, a Chinese-speaking operator assessed as based in Zhuhai. Hermes Agent handled orchestration (terminal access, Telegram command-and-control, skills). DeepSeek was the reasoning engine for code generation, vulnerability assessment, target selection, and decisions. Access went straight to DeepSeek’s API.
The actor customized Hermes with red-teaming skills, including a FOFA cyberspace-search procedure that drove an actor-written enumeration script, plus an open-source FofaMap MCP server for asset search and Nuclei scan generation. In a recovered May 7, 2026 session, Unit 42 says it saw almost no further human input after the initial task.
DeepSeek’s autonomous path looked like this: identify a high-severity CVE, download a public PoC from GitHub, enumerate internet-facing instances via FOFA, scan for vulnerable versions, then attempt exploitation. When Langflow stalled, the agent surveyed roughly 10 product families, searched GitHub for trending 2026 CVE PoCs by stars, and pivoted to n8n on severity and deployment footprint.
FOFA numbers in the report make the scale concrete: 84 Langflow instances from a title search; for n8n, more than 647,000 instances globally and about 25,200 in China. DeepSeek then sampled a fraction of Chinese n8n hosts to conserve compute, probing on the order of 40 IPs after sampling about 100 from the larger set.
Where autonomous exploits stalled
Against Langflow (CVE-2026-33017, CVSS 9.8), the agent downloaded a public PoC, found one instance on 1.3.4, and failed because the bug needed auto_login or a public flow ID. The target had neither. DeepSeek wrote the product off as low value and went looking for larger surface area.
Against n8n, it pulled a public PoC chaining CVE-2026-21858 (arbitrary file read, CVSS 10.0) and CVE-2025-68613 (sandbox bypass to RCE, CVSS 9.9). Three Chinese instances ran vulnerable versions. Forms that looked useful required authentication; the PoC needed an unauthenticated upload form. Parallel scans of 50-plus more targets found none with publicly accessible forms. No autonomous compromise.
Unit 42’s point: the margin of failure was configuration, not model inability. Weaker defaults would have fallen.
What still succeeded in manual follow-ons
Away from the Hermes loop, the same actor ran conventional FOFA-plus-Python campaigns with confirmed impact. Unit 42 reports:
Across autonomous and manual activity, the actor staged tooling for seven vulnerabilities and touched more than 460 targets. Manual ops delivered the breaches. AI ops delivered the speed: hours of targeting work compressed into minutes, with the model narrowing scope to save tokens.
The actor also evaluated other models. Claude Code and Codex traffic went through a third-party proxy; Qwen, GLM, Kimi, and MiniMax appeared in limited tests. OpenAI later told Unit 42 that provider-side safeguards refused policy-violating requests and disabled an account believed linked to the campaign.
Why the home-directory leak exposed the op
Responding to a Telegram command, Hermes started python3 -m http.server 8888 from /home/worker instead of an isolated staging folder.
The actor had emptied exploit directories after use and disabled Codex response storage elsewhere. Autonomy still handed researchers the whole workspace.
For defenders, the takeaway is narrower and uglier: agent tooling already chains FOFA, GitHub PoCs, and Telegram C2. Auth and sane defaults stopped the observed autonomous runs. Humans finished the job when the agent stalled. Patch Langflow, n8n, NetScaler, and the rest of the CVE list in the report.



