logo

Crims claim HexStrike AI penetration tool makes quick work of Citrix bugs

ID: cf490241-5b3a-5728-8a79-f09fb43ccb90

STIX ID: report--cf490241-5b3a-5728-8a79-f09fb43ccb90

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2025-09-03

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Check Point researchers report that CVE-2025-7775, a critical pre-auth remote code execution in Citrix NetScaler, was exploited as a zero-day to drop webshells and backdoor appliances prior to patching. Threat actors on underground forums have claimed rapid adoption of HexStrike AI—an open-source, LLM-orchestrated penetration-testing framework—to generate exploit code and scan for vulnerable NetScaler instances within hours of the disclosure, raising concerns that AI-driven tooling will dramatically shorten the window between disclosure and mass exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.