Unit 42 at Palo Alto Networks reports that a Chinese-speaking cyber threat actor employed the DeepSeek tool via the open-source Hermes Agent framework to carry out autonomous attacks This article explores exploitability organizations patch. . The operator, identified as knaithe and KnYuan, initiated exploitation attempts against over 460 targets through both autonomous and conventional workflows.
Unit 42 disclosed that a NetScaler memory-overread flaw was utilized in separate manual operations to exfiltrate data from three organizations, along with command execution on 11 Marimo instances through an unspecified method. The agent reviewed versions, downloaded exploits, abandoned an unproductive path, and selected a more severe vulnerability based on severity, deployment scale, and apparent exploitability.
Organizations must patch exposed Langflow, n8n, and Marimo systems, as well as customer-managed NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers. This resulted in unintended access to actor model configurations, API keys, exploit scripts, target lists, shell history, and autonomous-session logs as per the company’s report. Users should review their appliance configurations to ensure they include the 'authentication.samlIdPProfile' setting, then update with the patches provided by the company for enhanced security.
Public materials corroborate this assessment but do not independently verify it: the GitHub account shows "KnYuan Knaithe" and an older blog attributed to the same handle lists the author as a binary security researcher based in Zhuhai.












