Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

New AI-powered HexStrike tool is being used to target multiple Citrix security flaws

Tech Wavo by Tech Wavo
September 5, 2025
in Computers
0




  • A legitimate red teaming tool called HexStrike-AI is drawing the attention of the wrong crowd
  • Researchers are seeing “chatter” about the tool being leveraged to exploit known Citrix flaws
  • The patching window for system administrators keeps shrinking

Cybercriminals are using a legitimate red teaming tool to automate the exploitation of n-day vulnerabilities, reducing the time businesses have to fix flaws from days to literal minutes.

Security experts at Check Point Research said they observed “chatter” around the dark web of a tool called HexStrike-AI, an open source offensive security framework that connects large language models such as GPT, Claude, and Copilot with cybersecurity tools through the Model Context Protocol. It provides access to more than 150 tools for penetration testing, bug bounty automation, and vulnerability research, using multiple AI agents to manage workflows, analyze data, and run scanning, exploitation, or reporting tasks.

It is powered by an “Intelligent Decision Engine” that selects and executes tools based on the target environment, and supports network analysis, web application testing, cloud security checks, reverse engineering, and OSINT.


You may like

Citrix in the spotlight

Check Point Research says that hackers are sharing information on how to deploy HexStrike-AI to take advantage of CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424, three vulnerabilities recently discovered in Citrix NetScaler ADC and Gateway instances.

The tool allegedly helped them achieve unauthenticated remote code execution which, in turn, allowed them to drop webshells and maintain persistence.

While this chatter isn’t evidence enough of abuse, if confirmed, the news would mean the exploitation time can be cut down from several days to a few minutes, leaving system administrators with an already small patching window, and even less time before attacks begin.

“CVE-2025-7775 is already being exploited in the wild, and with Hexstrike-AI, the volume of attacks will only increase in the coming days,” CPR warned.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

With this level of automation, keeping software updated without a patch management platform will probably be impossible.

Via BleepingComputer

You might also like

Previous Post

Seagate’s Barracuda 24TB hard drive is the cheapest per TB right now, so act fast if you want one

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

New AI-powered HexStrike tool is being used to target multiple Citrix security flaws

by Tech Wavo
September 5, 2025
0
Farmers Insurance data breach sees over a million customers hit – here’s what we know
Computers

A legitimate red teaming tool called HexStrike-AI is drawing the attention of the wrong crowdResearchers are seeing "chatter" about the...

Read more

Seagate’s Barracuda 24TB hard drive is the cheapest per TB right now, so act fast if you want one

by Tech Wavo
September 5, 2025
0
Seagate’s Barracuda 24TB hard drive is the cheapest per TB right now, so act fast if you want one
Computers

If you're looking for huge amounts of additional storage, but don't want to pay over the odds for it, we...

Read more

How to watch NFL for *FREE* in the UK

by Tech Wavo
September 5, 2025
0
How to watch NFL for *FREE* in the UK
Computers

In a total touchdown for UK-based NFL fans, the 2025/26 regular season will see more games going out on free-to-air...

Read more

How to watch Women’s Super League free live streams 2025/26

by Tech Wavo
September 5, 2025
0
How to watch Women’s Super League free live streams 2025/26
Computers

Watch 2025/26 Women's Super League live streams as the likes of Arsenal and Manchester City aim to stop Chelsea defending...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock