AI Tooling Under Attack: DeepSeek Models Exposed by Vulnerabilities
A recent report claimed that a Chinese hacker used DeepSeek to attack over 460 systems with a single command, but further investigation has revealed that this claim may be exaggerated. While Palo Alto Networks did publish a report on the vulnerabilities of DeepSeek models, there is no evidence to support the claim that they were used in an autonomous intrusion campaign.
However, the underlying risk is still present. The National Vulnerability Database lists CVE-2026-33017 as an unauthenticated code injection flaw affecting Langflow versions before 1.9.0, and CISA added it to its Known Exploited Vulnerabilities catalog on March 25, 2026.
Langflow instances with this vulnerability are not theoretical bait for future hackers - they have already been exploited in the wild. Trend Micro researchers saw attackers using the Langflow flaw over a 19-day window between March 27 and April 15, 2026, to deploy a Monero miner on exposed AI application endpoints.
DeepSeek's safety record also raises concerns. Cisco researchers tested DeepSeek R1 against 50 HarmBench prompts and reported a 100% attack success rate. This suggests that DeepSeek models may not be effective in blocking harmful inputs.