A cybercriminal uses three open-source AI agents to attack more than 27 companies
Security firm Gambit has uncovered a campaign in which a Chinese-speaking attacker used artificial intelligence agents to compromise 27 organisations, including a Fortune 500 hospitality company, a major US airline, an industrial supplies distributor and an online fashion retailer. The criminal combined three open-source tools: Hermes, which acted as the orchestrator; Strix, which searched for vulnerabilities; and Cairn, which exploited them autonomously. Between 10 and 15 September the attacker launched 105 attacks and, on average, went from finding a flaw to exploiting it in a few hours or less than a day.
The agents exploited well-known flaws such as SQL injection, escalated privileges, stole Amazon cloud (AWS) credentials and planted backdoors on servers. On at least 19 websites they installed skimmers, code that steals card details at checkout, and they took more than 600,000 card records from two victims. The most worrying part is the cost: the AI bill came to around $25 per completed scan, and the whole campaign is estimated at between $12,000 and $18,000. AI makes attacks cheaper and faster, and any website with unpatched flaws becomes a target.
Tip from Soporte Informático 360
Keep your website, online shop and plugins up to date, because these agents hunt for known flaws at scale. Regularly check your checkout pages for unfamiliar code, protect your cloud service credentials with MFA and, if you sell online, use external payment gateways that don’t expose card details on your server.
Source: The Register. Summary prepared by our team for informational purposes.
IT maintenance for businesses
Preventive and corrective maintenance of your equipment to avoid downtime and extend its useful life.