CyberStrikeAI tool adopted by hackers for AI-powered attacks
2026-03-04T20:07:41Z•a07f6897eb9042dbcc570143eb83ca3cc0dcec3d68bc31b2d17cfbdab0b16a2a
CVE-2025-0282ai-enabled-attacksair-gap-bridgingapt37browser-extension-malwareclawjackedcredential-theftcryptocurrency-theftcybercrimefortinet-fortigateivanti-connect-securemfa-bypassopenclawphishingresurgevulnerability-exploit
What happened
Multiple high-impact incidents reported: an open-source security testing platform (CyberStrikeAI) has been adopted by attackers and linked to a campaign that breached hundreds of Fortinet FortiGate appliances; CISA warns of RESURGE implants persisting on Ivanti Connect Secure devices via an exploit for CVE-2025-0282; a phishing campaign is using a fake Google PWA to harvest credentials, MFA one-time codes, and proxy attacker traffic through victims' browsers; a malicious Chrome extension (QuickLens) was used to steal crypto; a Korean tax agency accidentally exposed a wallet seed that enabled a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a07f6897eb9042dbcc570143eb83ca3cc0dcec3d68bc31b2d17cfbdab0b16a2a
- Enrichment time
- 2026-03-04T20:07:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.