A Chinese-speaking threat actor used an AI-driven agent to search for vulnerable internet-facing servers and begin attacks with little direct human input. The campaign shows how automated tools can now move from finding targets to testing public exploits in a single workflow. The activity focused on exposed Langflow and n8n systems, before the operator also used traditional tools against Citrix NetScaler devices, Marimo notebooks, Apache Tomcat servers, and VPN endpoints. Although the AI-led attacks did not fully compromise their intended targets, the wider operation caused confirmed data theft and command execution. Researchers at Unit42 identified the campaign after the Hermes Agent mistakenly exposed its own working...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!