CyberStrikeAI tool adopted by hackers for AI-powered attacks

2026-03-04T20:05:33Z5d5b4f6a98c6ffdba45357ad1a8d66d40d78e5f119ba6691f3ea77d118e94f52
CVE-2025-0282ai-tool-abuseair-gapped-exfiltrationapt37browser-extension-malwareclawjackedcredential-theftcrypto-theftcyberstrikeaifortinet-fortigateivanti-connect-securemfa-bypassopenclawphishingpwaresurge

What happened

A set of active threats and security incidents was reported: attackers adopted the open-source AI security tool CyberStrikeAI in campaigns linked to breaches of hundreds of Fortinet FortiGate devices; a phishing campaign deployed a fake Google Account PWA to steal credentials, MFA one‑time codes, crypto wallet addresses, and proxy traffic through victims' browsers; a high‑severity 'ClawJacked' flaw in the OpenClaw AI agent allowed websites to hijack local instances; CISA warned that the RESURGE implant can remain dormant on Ivanti Connect Secure devices following exploitation of CVE-2025-0282;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
5d5b4f6a98c6ffdba45357ad1a8d66d40d78e5f119ba6691f3ea77d118e94f52
Enrichment time
2026-03-04T20:05:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CyberStrikeAI tool adopted by hackers for AI-powered attacks · Baitaphish