Attackers on underground forums claimed they were using HexStrike AI, an open-source red-teaming tool, against Citrix NetScaler vulnerabilities within hours of disclosure, according to Check Point cybersecurity evangelist Amit Weigman. The AI tool, and its near-instantaneous adoption by cybercriminals, signal "the window between disclosure and mass exploitation shrinks dramatically," Weigman wrote in a Tuesday blog. CVE-2025-7775, a critical, pre-auth remote code execution bug, was abused as a zero-day to drop webshells and backdoor appliances before Citrix issued a patch. "And with HexStrike AI, the volume of attacks will only increase in the coming days," Weigman warned. HexStrike AI is an AI-powered penetration testing framework developed by security researcher Muhammad Osama and released on GitHub several weeks ago. The offensive security utility integrates with more than 150 security tools to perform network reconnaissance and scanning, web application security testing, reverse engineering and a slew of other tasks. It also connects to more than a dozen AI agents to scan for vulnerabilities, automate exploit development, and discover new attack chains. The GitHub repository warns that HexStrike AI shouldn't be used for unauthorized system testing, illegal or harmful activities, or data theft. However, shortly after its release, criminals — as they are wont to do with any type of legitimate pen-testing tool — began discussing HexStrike AI in the context of the Citrix secu...
Crims claim HexStrike AI penetration tool makes quick work of Citrix bugs
The Register
·Jessica Lyons
·Published Sep 3, 2025
·Updated
Affected Software
2 affected components
Citrix NetScaler
HexStrike AI
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the use of the HexStrike AI penetration tool by attackers to exploit vulnerabilities in Citrix NetScaler shortly after their disclosure.
2
What security implications are discussed?
The article highlights the rapid exploitation of Citrix vulnerabilities using an AI tool, raising concerns about the speed at which attackers can leverage newly disclosed security flaws.
3
What products or software are affected?
The affected products mentioned in the article are Citrix NetScaler and the HexStrike AI tool.
4
Who disclosed the information about the exploitation of Citrix vulnerabilities?
Check Point cybersecurity evangelist Amit discussed the use of HexStrike AI against Citrix vulnerabilities.
5
What does HexStrike AI do in relation to cybersecurity?
HexStrike AI is described as an open-source red-teaming tool that assists attackers in exploiting security vulnerabilities.