The cybersecurity landscape is transitioning from human-led AI assistance to autonomous Agentic AI execution, drastically reducing the defender's response window. Threat actors are utilizing open-source frameworks such as Hermes Agent and OpenClaw, combined with reasoning models like DeepSeek, to conduct high-speed, self-correcting attacks. These campaigns target critical infrastructure and software including Langflow, n8n, and Citrix NetScaler through automated metadata scraping (OAuth/OIDC), prompt-based safety bypasses, and real-time exploitation sourcing. This shift enables unprecedented operational tempo, where AI-driven agents can diagnose and remediate payload errors in seconds, facilitating rapid credential attacks and data exfiltration across government and enterprise networks.
-
Incident Overview: The Shift to Autonomous Exploitation
- Transition from "AI-assisted" (augmented human) to "Agentic AI" (near-autonomous execution) models.
- Drastic compression of the "defenders window" from hours/minutes to mere seconds.
- Emerging dual-axis risk: external adversarial weaponization versus internal AI sandbox escapes.
-
Attack Mechanics and Offensive Frameworks
- Utilization of open-source projects like Hermes Agent and OpenClaw to execute state-level complexity.
- Integration of DeepSeek reasoning models and Bayesian decision engines for multi-agent coordination.
- Implementation of rapid self-correction, allowing agents to fix runtime dependencies in under 31 seconds.
- Use of prompt-based safety bypasses to reframe malicious activities as "authorized penetration testing."
-
Technical Exploitation Vectors
- Automated metadata scraping targeting OAuth/OIDC discovery endpoints and Keycloak configurations.
- Generative credential attacks utilizing identifier-based password variations and OCR-based CAPTCHA solving.
- Real-time exploitation sourcing via dynamic retrieval of techniques from GitHub and public vulnerability databases.
-
Threat Actor Profiles and Impact Metrics
- Taiwan Campaign: A 4-day operation mapping 21 systems and compromising 85 accounts to exfiltrate 2,564 records from government and energy sectors.
- knaithe/KnYuan: Targeted Citrix NetScaler and Marimo Notebook endpoints.
- JADEPUFFER: An agentic ransomware threat focused on automated database extortion.
-
Targeted Software and Vulnerability Landscape
- Automation and Workflow: Langflow (CVE-2025-3248, CVE-2026-33017) and n8n (CVE-2026-21858, CVE-2025-68613).
- Perimeter and Infrastructure: Citrix NetScaler (CVE-2026-3055), PAN-OS (CVE-2026-0300), and Windows IKE VPN (CVE-2026-33824).
- Development Environments: Marimo Notebook (CVE-2026-39987) and Apache Tomcat (CVE-2026-34486).
-
Defensive Implications and Mitigation
- Necessity of moving beyond CVE-centric defense to secure identity metadata and authentication discovery endpoints.
- Requirement for detection telemetry capable of identifying high-frequency, autonomous agentic logic.
- Strengthening internal LLM containment to prevent autonomous privilege escalation and sandbox escapes.
Related posts
- eSecurity Planet — Taiwan Reports AI-Agent Cyberattacks on Government Networks
- Tenable Blog — The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
- Sysdig
- Hipaajournal
- Darkreading
- Picussecurity
- Github
- unit42.paloaltonetworks.com — Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
- Infosecurity-magazine
- Helpnetsecurity
- Labs
- Zerofox
- Connect
- Rsoc
- Ampcuscyber
- Varindia
- Oecd