Hackers are increasingly using a new AI-powered offensive security framework called HexStrike-AI in real attacks to exploit newly disclosed n-day flaws. This activity is reported by CheckPoint Research, which observed significant chatter on the dark web around HexStrike-AI, associated with the rapid weaponization of newly disclosed Citrix vulnerabilities, including CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424. According to ShadowServer Foundation's data, nearly 8,000 endpoints remain vulnerable to CVE-2025-7775 as of September 2, 2025, down from 28,000 the previous week. HexStrike-AI is a legitimate red teaming tool created by cybersecurity researcher Muhammad Osama, which enables the integration of AI agents to autonomously run over 150 cybersecurity tools for automated penetration testing and vulnerability discovery. "HexStrike AI operates with human-in-the-loop interaction through external LLMs via MCP, creating a continuous cycle of prompts, analysis, execution, and feedback," reads its creator's description. HexStrike-AI's client features a retry logic and recovery handling to mitigate the effects of failures in any individual step on its complex operations. Instead, it automatically retries or adjusts its configuration until the operation completes successfully. The tool has been open-source and available on GitHub for the last month, where it has already garnered 1,800 stars and over 400 forks. Unfortunately, it has also attracted the attention of hackers who have ...
Hackers use new HexStrike-AI tool to rapidly exploit n-day flaws
BleepingComputer
·Bill Toulas
·Published Sep 3, 2025
·Updated
Affected Software
1 affected component
Citrix Citrix
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the use of the HexStrike-AI tool by hackers to exploit n-day security flaws.
2
What security implications are discussed?
The article highlights the risks posed by the rapid exploitation of vulnerabilities using AI-powered tools like HexStrike-AI.
3
What software is specifically mentioned as being affected?
The article mentions Citrix as one of the affected software products.
4
How does HexStrike-AI enhance hacking capabilities?
HexStrike-AI enables hackers to quickly identify and exploit vulnerabilities by automating the attack process.
5
What organization reported on the use of HexStrike-AI?
CheckPoint Research is the organization that reported the significant usage of HexStrike-AI in cyber attacks.