CyberStrikeAI tool adopted by hackers for AI-powered attacks

2026-03-04T20:07:41Za07f6897eb9042dbcc570143eb83ca3cc0dcec3d68bc31b2d17cfbdab0b16a2a
CVE-2025-0282ai-enabled-attacksair-gap-bridgingapt37browser-extension-malwareclawjackedcredential-theftcryptocurrency-theftcybercrimefortinet-fortigateivanti-connect-securemfa-bypassopenclawphishingresurgevulnerability-exploit

What happened

Multiple high-impact incidents reported: an open-source security testing platform (CyberStrikeAI) has been adopted by attackers and linked to a campaign that breached hundreds of Fortinet FortiGate appliances; CISA warns of RESURGE implants persisting on Ivanti Connect Secure devices via an exploit for CVE-2025-0282; a phishing campaign is using a fake Google PWA to harvest credentials, MFA one-time codes, and proxy attacker traffic through victims' browsers; a malicious Chrome extension (QuickLens) was used to steal crypto; a Korean tax agency accidentally exposed a wallet seed that enabled a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
a07f6897eb9042dbcc570143eb83ca3cc0dcec3d68bc31b2d17cfbdab0b16a2a
Enrichment time
2026-03-04T20:07:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CyberStrikeAI tool adopted by hackers for AI-powered attacks · Baitaphish