Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
Campaign
Summary
Hide ▲
Show ▼
The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and exploitation over Telegram against internet-exposed infrastructure in Asia. The activity blended autonomous and manual exploitation, scanned 10 product families, and pivoted across multiple CVEs, including CVE-2026-3055, CVE-2026-39987, and CVE-2026-33824. A later CISA update on August 5, 2026 added CVE-2026-34486 in Apache Tomcat to the KEV catalog for active exploitation, and the article says that exploitation of that Tomcat flaw was attributed to the same knaithe / KnYuan campaign. Impact remained limited overall, with no full compromise of intended targets in the earlier reporting, but the event shows a reusable intrusion pattern that can scale across exposed systems.
Related Happenings
HashiCorp security patch release for CVE-2026-16498
Security Patch Release
H score37
First: 05.08.2026 17:27
Last: 05.08.2026 17:27
Sources 1
About this happening:
HashiCorp released Terraform MCP Server 1.1.0 to fix three Streamable HTTP flaws, including CVE-2026-16498 token reuse and CVE-2026-14869 SSRF, that could affect s...
HashiCorp security patch release for CVE-2026-16498
Security Patch ReleaseAbout this happening: HashiCorp released Terraform MCP Server 1.1.0 to fix three Streamable HTTP flaws, including CVE-2026-16498 token reuse and CVE-2026-14869 SSRF, that could affect s...
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentAbout this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)
Vulnerability
H score49
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
How related:
Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central. It's worth noting that an incomplete fix for this issue prompted N-able to issue a fresh patch, which is tracked as CVE-2026-18577 (CVSS score: 8.2).
About this happening:
CVE-2026-18577 is an authentication bypass in N-able N-central that affects hosted and on-premises servers before 2026.3. N-able said the issue stems from an i...
N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)
VulnerabilityHow related: Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central. It's worth noting that an incomplete fix for this issue prompted N-able to issue a fresh patch, which is tracked as CVE-2026-18577 (CVSS score: 8.2).
About this happening: CVE-2026-18577 is an authentication bypass in N-able N-central that affects hosted and on-premises servers before 2026.3. N-able said the issue stems from an i...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.
Trim ecosystem shift changes threat-actor operations
Threat Actor Meta
H score22
First: 21.07.2026 17:00
Last: 21.07.2026 17:00
Sources 1
About this happening:
Trim shifted from publishing Claude Opus jailbreak techniques to selling AI Pentest Checker, accelerating the commercialization of jailbreak-based offensive tooling. T...
Trim ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Trim shifted from publishing Claude Opus jailbreak techniques to selling AI Pentest Checker, accelerating the commercialization of jailbreak-based offensive tooling. T...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Timeline
-
30.07.2026 03:00 3 articles · 8d ago
Unit 42 details AI-orchestrated exploitation against exposed infrastructure in Asia
Initial DisclosureUnit 42 reported that a Chinese-speaking operator using the aliases knaithe and KnYuan, based in Zhuhai, China, used Hermes Agent with a DeepSeek AI model and other LLMs over Telegram to orchestrate exploitation against internet-exposed infrastructure in Asia. The workflow combined autonomous AI-driven enumeration and automated exploitation with manual exploitation, scanned 10 product families, pivoted to seven CVEs including CVE-2026-3055, CVE-2026-39987, and CVE-2026-33824, and showed limited impact without full compromise of intended targets in China and Malaysia.
Show sources
- Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits — www.infosecurity-magazine.com — 31.07.2026 18:00
- Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits — www.infosecurity-magazine.com — 31.07.2026 18:00
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited — thehackernews.com — 05.08.2026 10:40