A Campaign Traced Back to Zhuhai

On 2026-05-07, researchers at Unit 42, Palo Alto Networks' threat intelligence arm, began tracking a campaign run by a Chinese-speaking threat actor operating under the handles knaithe and KnYuan, assessed to be based in Zhuhai. What made the campaign distinct was not the exploit code itself, but who - or what - was choosing when and where to use it.

The actor built the campaign around a framework Unit 42 calls Hermes Agent, which used DeepSeek, the Chinese AI model, to autonomously enumerate vulnerable targets and select which exploit to fire next. Unit 42's research, published on 2026-07-30, describes an operation where no human sat in the loop at the exploit-selection stage - the AI decided.

CISA's Emergency Order: Three CVEs, Two Days

On 2026-08-05, the US Cybersecurity and Infrastructure Security Agency added three vulnerabilities from this campaign to its Known Exploited Vulnerabilities catalog: CVE-2026-9198, a remote code execution flaw in Langflow carrying a CVSS score of 9.8; CVE-2026-34486 in Apache Tomcat; and CVE-2026-18556 in N-able N-central. All three showed confirmed active exploitation tied to the Hermes Agent campaign.

CISA set a federal remediation deadline of 2026-08-07 - two days from the catalog addition - for US federal civilian agencies running the affected software. The Hacker News confirmed the addition and the deadline in coverage published on 2026-08-06, underscoring how unusual the compressed timeline is even by KEV standards.

460 Organizations, Three Countries, Confirmed Breaches

Unit 42's research ties the campaign to 460 or more organizations across three countries, using seven CVEs in total across the operation - the three CISA added to KEV, plus vulnerabilities in Citrix NetScaler, Marimo Notebook, PAN-OS, and n8n, the last carrying a maximum CVSS score of 10.0.

The impact was not theoretical. Unit 42 confirmed data exfiltration from three Citrix NetScaler victims, command execution achieved on eleven Marimo Notebook endpoints, session-hijacking attempts using stolen authentication cookies, and sustained targeting of a Malaysian government entity.

The Real Escalation Is Not the Exploit Code

The headline detail is not that an AI model touched a hacking operation - AI-assisted reconnaissance and code generation are already common. The escalation is that Hermes Agent used DeepSeek to make the targeting decision itself: which of seven CVEs to fire, against which of hundreds of organizations, without a human choosing in the moment.

That autonomy changes attacker economics. A campaign that once needed operators triaging targets one by one can now let a model do the enumeration and selection at machine speed, which is how a single actor working under one or two handles reached 460-plus organizations across three countries without a matching increase in headcount.

What EU and UK Operators Should Do Before Friday

CISA's 2026-08-07 deadline binds US federal civilian agencies, not European or UK organizations directly, but the underlying signal applies everywhere the same software runs: any exposed instance of Apache Tomcat, Langflow, or N-able N-central sat inside a campaign that an AI agent was actively targeting as of early August 2026. Waiting for a routine patch cycle is not a safe posture for these three products right now.

Operators should also check session management around Citrix NetScaler and similar remote-access products, given the confirmed session-hijacking attempts using stolen cookies, and should not assume small size or low profile offers protection - Unit 42's own numbers show the campaign pivoted through hundreds of organizations that were reached, not specifically chosen.