AI Agent Turns Public CVEs Into Faster Attacks

Public CVEs are no longer just a patching problem. An attacker can hand discovery, exploit search, and target switching to an agent and get machine-speed retries after a failed first hit, which lowers the skill and time needed to weaponize disclosed flaws. Unit 42 says a Chinese-speaking actor, using DeepSeek through Hermes Agent and several other LLMs, autonomously enumerated targets, pulled public proof-of-concepts, and pivoted across seven disclosed CVEs. The activity touched Langflow, n8n, Apache Tomcat, Palo Alto Networks PAN-OS, Citrix NetScaler ADC/NetScaler Gateway, and marimo, with confirmed impact. The practical change is speed and persistence across product families. A failed exploit no longer ends the campaign if the operator is an agent that can keep searching adjacent CVEs and try again without waiting on a human.

Part of the PlainSec briefing for 2026-07-30

Sources