Find notable cyber news and cases, enriched with sources, timelines, and signals.

Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

The knaithe / KnYuan campaign used LLMs and Hermes Agent over Telegram to automate enumeration and exploitation against internet-exposed infrastructure in Asia, increasing the speed and scale of attacks across China and Malaysia. The operator blended autonomous AI-driven scanning with manual exploitation and tested multiple models, including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI Codex. The run touched 10 product families and pivoted to seven CVEs, including CVE-2026-3055 and CVE-2026-39987. Impact stayed limited, with no full compromise of intended targets, but the workflow shows a reusable AI-assisted intrusion pattern.

Related Happenings

Trim ecosystem shift changes threat-actor operations

Threat Actor Meta
H score22 First: 21.07.2026 17:00 Last: 21.07.2026 17:00 Sources 1

About this happening: Trim shifted from publishing Claude Opus jailbreak techniques to selling AI Pentest Checker, accelerating the commercialization of jailbreak-based offensive tooling. T...

CL-STA-1062 Southeast Asia critical infrastructure campaign using TinyRCT

Campaign
H score18 First: 26.06.2026 13:30 Last: 26.06.2026 13:30 Sources 1

About this happening: A China-linked campaign by CL-STA-1062 is targeting government entities and critical infrastructure across Southeast Asia, with activity reaching state-owned...

GREYVIBE's Kremlin-aligned role in the Russian cybercrime ecosystem

Threat Actor Meta
H score15 First: 29.05.2026 14:31 Last: 29.05.2026 14:31 Sources 1

About this happening: A newly characterized GREYVIBE actor sits in a grey zone between Kremlin-aligned intelligence work and the Russian cybercrime ecosystem, complicating attribution f...

Shadow-Aether-040 AI-augmented campaign against Mexican government entities

Campaign
H score41 First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: The Shadow-Aether-040 campaign used AI agents and custom tooling to compromise six government entities in Mexico, increasing the risk of follow-on intrusion and data...

Google GTIG analysis of adversary AI use for exploit development and attack orchestration

Technical Analysis
H score33 First: 11.05.2026 16:00 Last: 11.05.2026 16:00 Sources 1

About this happening: Google Threat Intelligence Group published findings showing adversaries using AI for exploit development and attack orchestration, signaling that model-assisted tr...

Timeline

  1. 30.07.2026 03:00 2 articles · 2d ago

    Unit 42 details AI-orchestrated exploitation against exposed infrastructure in Asia

    Initial Disclosure

    Unit 42 reported that a Chinese-speaking operator using the aliases knaithe and KnYuan, based in Zhuhai, China, used Hermes Agent with a DeepSeek AI model and other LLMs over Telegram to orchestrate exploitation against internet-exposed infrastructure in Asia. The workflow combined autonomous AI-driven enumeration and automated exploitation with manual exploitation, scanned 10 product families, pivoted to seven CVEs including CVE-2026-3055, CVE-2026-39987, and CVE-2026-33824, and showed limited impact without full compromise of intended targets in China and Malaysia.

    Show sources