Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

Aug 03, 2026 - 17:00

A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s AI agent misconfigured a file server, inadvertently exposing the entire infrastructure. “This visibility enabled us to understand their full tool set, how the attackers orchestrated multiple AI platforms and gave us a peek into their targeting,” Unit … More

The post Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers appeared first on Help Net Security.