The use of artificial intelligence in cybersecurity is taking on a disturbing new dimension as researchers reveal that the open-source security testing platform CyberStrikeAI is linked to the same threat entity that breached hundreds of Fortinet FortiGate firewalls. The case highlights how AI tools, theoretically designed for defensive purposes, can become a force multiplier for attackers.

Last month, BleepingComputer uncovered an AI-powered hacking campaign that compromised over 500 Fortinet FortiGate devices in just five weeks. The attacker exploited multiple servers, including a web server at 212.11.64[.]250, which is now the focus of new findings.
IP connection and NetFlow analysis
In a recent analysis, Will Thomas of Team Cymru identified the same IP address as hosting the CyberStrikeAI. Through NetFlow, the team observed a “CyberStrikeAI” service banner on port 8080 at 212.11.64[.]250, as well as network communication between this infrastructure and the targeted FortiGate devices.
See also: Vulnerability in MS-Agent allows complete system compromise
The campaign infrastructure reportedly ran CyberStrikeAI until January 30, 2026, further linking the tool to the attack. While the use of an open-source platform does not in itself prove state involvement or a specific perpetrator, the pattern of activity is deeply concerning.
What is CyberStrikeAI?
On GitHub, CyberStrikeAI is described as an “AI-driven security testing platform” written in Go. It integrates more than 100 security tools, an intelligent orchestration engine, security roles, and a skills system. It supports AI decision engines through models such as GPT, Claude, and DeepSeek, and features a password-protected web interface with audit logging and SQLite persistence. There is also a dashboard for vulnerability management, task orchestration, and attack chain visualization.

In practice, the tool can perform a full attack chain: from reconnaissance with nmap and masscan, to exploitation via metasploit and pwntools, code cracking with hashcat and john, as well as post-exploitation moves with mimikatz or bloodhound. The combination of these with AI agents drastically reduces the need for deep technical training of attackers.
See also: Chrome Vulnerability: Malicious Extensions and Gemini Panel
Automated targeting on edge devices
Team Cymru warns that such AI-native orchestration engines accelerate the automated targeting of vulnerable edge devices, such as firewalls and VPN gateways. Between January 20 and February 26, 2026, 21 unique IPs were identified running CyberStrikeAI, with servers primarily in China, Singapore and Hong Kong, but also in the US, Japan and Europe.
The geographical spread shows that the platform is not an isolated experiment, but is part of a broader ecosystem of tools that enable mass mapping and exploitation of vulnerabilities.
The programmer and the interfaces
The creator's profile (Ed1s0nZ), reveals additional tools such as PrivHunterAI and InfiltrateX, which focus on detecting and exploiting privilege escalation vulnerabilities. According to Team Cymru, GitHub activity shows interactions with organizations that have previously been associated with Chinese cyber operations.
In December 2025, CyberStrikeAI was shared with Knownsec ’s “ Starlink Project , ” a company that has been accused of ties to Chinese state agencies. Additionally, the developer reported receiving an award from CNNVD . The China National Vulnerability Database (CNNVD) is believed to be operated by China’s intelligence community, which reportedly uses it to identify vulnerabilities for its operations. Team Cymru reports that the reference to CNNVD has been removed from the developer’s profile.
See also: Deepfakes and injection attacks breach identity verification
The developer's GitHub repositories are written primarily in Chinese, suggesting that this is a Chinese-speaking developer, and interaction with domestic cybersecurity organizations would not necessarily be unusual.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Bigger Picture: AI as an Attack Accelerator
The CyberStrikeAI case confirms a trend already being recorded internationally: commercial and open-source AI is being exploited by threat actors to automate attacks. Recently, Google warned that Gemini is being misused in multiple stages of cyberattacks, from reconnaissance to social engineering.
The critical element is reducing the “cost of entry.” Where once specialized red teaming was required, now a less experienced operator can, with the help of AI orchestration, execute complex attacks. For defenders, this means that the speed of detection and response must increase dramatically.
The next day in cybersecurity will not be determined only by new firewalls or patches, but by who will most effectively leverage artificial intelligence: the attackers or the defenders.
Source: www.bleepingcomputer.com
