Find notable cyber news and cases, enriched with sources, timelines, and signals.

Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia

Campaign
First reported
Last updated
Happening score
H score 47
2 unique sources, 2 articles

Summary

Hide ▲

The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and exploitation over Telegram against internet-exposed infrastructure in Asia. The activity blended autonomous and manual exploitation, scanned 10 product families, and pivoted across multiple CVEs, including CVE-2026-3055, CVE-2026-39987, and CVE-2026-33824. A later CISA update on August 5, 2026 added CVE-2026-34486 in Apache Tomcat to the KEV catalog for active exploitation, and the article says that exploitation of that Tomcat flaw was attributed to the same knaithe / KnYuan campaign. Impact remained limited overall, with no full compromise of intended targets in the earlier reporting, but the event shows a reusable intrusion pattern that can scale across exposed systems.

Related Happenings

HashiCorp security patch release for CVE-2026-16498

Security Patch Release
H score37 First: 05.08.2026 17:27 Last: 05.08.2026 17:27 Sources 1

About this happening: HashiCorp released Terraform MCP Server 1.1.0 to fix three Streamable HTTP flaws, including CVE-2026-16498 token reuse and CVE-2026-14869 SSRF, that could affect s...

N-able N-central servers hit by network compromise

Incident
H score41 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
H score49 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

How related: Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central. It's worth noting that an incomplete fix for this issue prompted N-able to issue a fresh patch, which is tracked as CVE-2026-18577 (CVSS score: 8.2).

About this happening: CVE-2026-18577 is an authentication bypass in N-able N-central that affects hosted and on-premises servers before 2026.3. N-able said the issue stems from an i...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.

Trim ecosystem shift changes threat-actor operations

Threat Actor Meta
H score22 First: 21.07.2026 17:00 Last: 21.07.2026 17:00 Sources 1

About this happening: Trim shifted from publishing Claude Opus jailbreak techniques to selling AI Pentest Checker, accelerating the commercialization of jailbreak-based offensive tooling. T...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

Timeline

  1. 30.07.2026 03:00 3 articles · 8d ago

    Unit 42 details AI-orchestrated exploitation against exposed infrastructure in Asia

    Initial Disclosure

    Unit 42 reported that a Chinese-speaking operator using the aliases knaithe and KnYuan, based in Zhuhai, China, used Hermes Agent with a DeepSeek AI model and other LLMs over Telegram to orchestrate exploitation against internet-exposed infrastructure in Asia. The workflow combined autonomous AI-driven enumeration and automated exploitation with manual exploitation, scanned 10 product families, pivoted to seven CVEs including CVE-2026-3055, CVE-2026-39987, and CVE-2026-33824, and showed limited impact without full compromise of intended targets in China and Malaysia.

    Show sources