SecureLayer7 A.I CyberSecurity Scoring
SecureLayer7
Company Information
Website:https://securelayer7.net/
Employees number:128
Number of followers:42,733
NAICS:541514
Industry Type:Computer and Network Security
Homepage:securelayer7.net
SecureLayer7 Risk Score (AI oriented)
Between 750 and 799
SecureLayer7Computer and Network Security
Updated:
31/07/2026
31/07/2026
751/1000
Fair
Baa
SecureLayer7 Global Score (TPRM)
xxxx
SecureLayer7Computer and Network Security
Score locked

SecureLayer7Fair
Current Score
751Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
751
AUGUST 2026
751
JULY 2026
751
JUNE 2026
751
MAY 2026
752
Vulnerability
01 May 2026 • SecureLayer7
Citrix, Microsoft, Apache Software Foundation and Langflow: Hacker uses DeepSeek AI to autonomously attack vulnerable servers
Chinese Threat Actor Leverages AI for Autonomous Cyberattacks
750
CRITICAL-2
MICTHESECCIT1785522270
Chinese Threat Actor Leverages AI for Autonomous Cyberattacks
Researchers at Palo Alto Networks’ Unit 42 have uncovered a campaign by a China-based threat actor using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks with minimal human oversight. The actor, operating under the aliases "knaithe" and "KnYuan," identifies as a "binary security researcher."
The discovery stemmed from an accidental exposure of the attacker’s environment after Hermes created a misconfigured web server, revealing API keys, exploit scripts, target lists, shell history, and AI attack logs. While the observed attacks did not successfully compromise targets, they demonstrated a fully autonomous offensive AI workflow capable of identifying, evaluating, and exploiting vulnerabilities.
### AI-Powered Attack Workflow
The threat actor deployed DeepSeek as the reasoning engine behind Hermes Agent, an AI framework that interacts with operating systems, executes commands, and connects to the internet. Hermes was configured to:
- Receive instructions via Telegram
- Use custom offensive-security tools
- Query FOFA, an internet asset search engine
- Operate in "Yolo" mode, executing commands without prior approval
In a recovered session from May 2026, the agent autonomously:
1. Targeted Langflow servers vulnerable to CVE-2026-33017, scanning 84 exposed instances but failing to exploit them.
2. Switched to n8n workflow automation, identifying 647,000 exposed instances and attempting to exploit CVE-2026-21858 and CVE-2025-68613 though authentication requirements prevented successful breaches.
3. Analyzed public exploit repositories and executed hundreds of hours of manual targeting analysis in minutes, managing its own compute resources.
### Manual Attacks & Successful Compromises
While the AI-driven attacks were largely unsuccessful, the threat actor also conducted manual attacks on 460+ systems, exploiting vulnerabilities in:
- Citrix NetScaler (CVE-2026-3055) – Used in three confirmed breaches to extract memory and harvest authentication cookies.
- Apache Tomcat, Marimo Notebook, Windows IKE VPN, and others.
Additional AI platforms (Qwen, GLM, Kimi, MiniMax, Claude Code, OpenAI Codex) were configured but rarely used.
### Previous Hermes Incident in Thailand
This campaign follows a separate incident where poorly secured Hermes infrastructure exposed details of an alleged cyberattack on Thailand’s Ministry of Finance. Logs revealed Hermes operating in unattended "YOLO" mode, automating post-exploitation tasks such as:
- Privilege escalation checks
- Service enumeration
- File system traversal
- Document cataloging
Unlike the autonomous attacks observed by Unit 42, the Thailand incident involved human-directed targeting, with Hermes only automating post-compromise activity.
### Significance of the Campaign
Unit 42 highlights the evolution of AI-driven cyber threats, where autonomous agents can:
- Research vulnerabilities independently
- Prioritize targets
- Download and execute exploits
- Adapt attack strategies in real time
While this campaign had limited success, it underscores the growing sophistication of offensive AI in cyber operations.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
752
MARCH 2026
752
FEBRUARY 2026
752
JANUARY 2026
752
DECEMBER 2025
752
NOVEMBER 2025
752
OCTOBER 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SecureLayer7 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in August 2026 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in July 2026 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in June 2026 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in May 2026 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in April 2026 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in March 2026 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in February 2026 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in January 2026 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in December 2025 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in November 2025 ??
What was SecureLayer7's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on SecureLayer7's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SecureLayer7 ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SecureLayer7's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?