Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Palo Alto Networks' Unit 42 reports a Chinese-speaking threat actor who used DeepSeek through the open-source Hermes Agent framework to launch autonomous attacks. After an initial Telegram instruction, the agent independently identified and exploited internet-facing systems, with no further operator input recovered.
A Chinese-speaking threat actor, tracked as knaithe or KnYuan, used the AI-powered DeepSeek model within the Hermes Agent framework to autonomously launch cyberattacks via Telegram commands. The attacks targeted over 460 systems, leveraging eight CVEs, including vulnerabilities in Langflow (CVE-2026-33017), n8n (CVE-2026-21858 and CVE-2025-68613), and NetScaler (CVE-2026-3055).
Unit 42 reports that a Chinese-speaking threat actor used DeepSeek through the Hermes Agent framework to launch autonomous attacks against over 460 targets. The agent selected public exploits and switched approaches, but many attempts failed due to configuration mismatches.
Researchers at AhnLab describe a campaign that delivers the AtlasRAT remote access Trojan through a fake Flash Player installer. The infection chain starts with a Delphi executable named FlashPlay.Exe and uses fileless techniques to reconstruct payloads entirely in memory.
Researchers at Malwarebytes have uncovered a campaign distributing the remote access Trojan (RAT) AtlasRAT through a fake Adobe Flash Player installer. Despite Adobe ending support for Flash Player on December 31, 2020, and blocking Flash content, users continue to search for Flash to access legacy content, making them vulnerable.
Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer.