HomeSecurityHackers leverage Hexstrike-AI for Zero Day exploit

Hackers leverage Hexstrike-AI for Zero Day exploit

Malicious actors are rapidly leveraging Hexstrike-AI, a newly released AI-based offensive security framework, to detect and exploit zero-day CVEs in less than ten minutes. Initially promoted as an offensive security framework for red teams, Hexstrike-AI’s architecture has already been repurposed by malicious actors within hours of its public release.

See also: Critical Citrix Zero-Day Exposes Global Organizations

Hexstrike-AI

Checkpoint’s recent analysis shows how AI can manage and simplify complex attacks by coordinating multiple specialized agents. This AI-based system helps automate multi-step attacks more efficiently. With Hexstrike-AI, this theory has been put into action. The framework is based on a FastMCP, connecting large language models (Claude, GPT, Copilot) to over 150 security tools via MCP decorators. AI agents can call standard functions such as nmap_scan(target, options) and execute_exploit(cve_id, payload) without human micromanagement.

Dark-web conversations confirmed that threat actors are testing Webshell deployments against the recently disclosed Citrix NetScaler ADC and Gateway CVEs CVE-2025-7775, CVE-2025-7776 , and CVE-2025-8424 within hours of their disclosure. Hexstrike-AI’s MCP orchestration layer interprets high-level commands, such as “NetScaler exploit,” into technical, sequenced workflows. Each stage of discovery, memory management exploitation, webshell persistence, and data extraction is handled by specialized MCP agents, ensuring re-execution logic and automated resilience.

See also: 28,000+ Citrix instances vulnerable to zero-day vulnerability

Hackers leverage Hexstrike-AI for Zero Day exploit

CheckPoint observed that, according to the posts, the operators achieved unauthenticated remote code execution on vulnerable devices and installed web shells in less than ten minutes. This model reflects academic predictions about the AI ​​orchestration driving next-generation attacks on the Hexstrike-AI code. Citrix’s advisory on August 26th revealed three critical NetScaler vulnerabilities.

Traditionally, exploiting such memory and access control flaws required specialized reverse engineering and exploit writing. Hexstrike-AI breaks down this barrier by enabling parallel scanning of thousands of IPs and dynamically adjusting exploit parameters until success. The time to exploit for CVE-2025-7775 has already been reduced from weeks to minutes, with webshell-equipped devices appearing on the underground markets. Organizations must accelerate patch cycles and implement adaptive AI-powered detection systems. Static signatures will not be sufficient against rapidly orchestrated attacks.

See also: Hacker says he's selling Windows Zero-Day RCE exploit

Hackers leverage Hexstrike-AI for Zero Day exploit

Monitoring dark-web intelligence for early signals, enforcing segmentation and least privilege models, and incorporating autonomous response books are critical. Defenders must keep up with the growth of AI-driven attacks through telemetry correlation and machine-speed patch verification.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS