Threat actors are increasingly operationalizing AI and automation to scale attacks and exploit weak controls across both enterprise and consumer environments. An open-source offensive platform dubbed CyberStrikeAI—a Go-based “AI-native security testing” framework integrating 100+ tools—was observed in infrastructure used to target Fortinet FortiGate edge devices at scale; researchers linked activity to an IP (212.11.64.250) exposing a CyberStrikeAI banner and to scanning/communications patterns consistent with mass exploitation. Separately, a newly disclosed and rapidly patched OpenClaw vulnerability showed how AI agent tooling can be hijacked: researchers reported that a malicious website could take over a developer’s locally running agent due to inadequate trust-boundary validation, prompting urgent upgrades to OpenClaw v2026.2.25+. In parallel, a “vibe-coding” hosted app on the Lovable platform leaked data impacting 18,000+ users after a researcher found 16 flaws (six critical) tied to mis-implemented backend controls (including missing/incorrect row-level security in Supabase), enabling unauthorized access to records and actions like bulk email and account deletion.
Criminal monetization also continues to evolve beyond AI-agent risks. AuraStealer, a Russian-language infostealer positioned as a successor/competitor after Lumma disruptions, was advertised on multiple underground forums and is supported by a sizable C2 footprint; analysis of 200+ samples identified 48 C2 domains, with operators abusing low-cost TLDs (e.g., .shop, .cfd) and using Cloudflare as a reverse proxy to mask origin infrastructure. Broader reporting and commentary reinforced that identity and access failures remain a dominant breach driver and that AI adoption is expanding the attack surface via over-privileged agents and “shadow AI,” while ransomware operators increasingly target recovery paths (including backups) and dwell to corrupt restore points. Several items in the set were non-incident thought leadership or workforce content (skills gap, jobs listings, awards, and general AI security tips) and did not add event-specific technical details beyond high-level risk framing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
The CyberStrikeAI report described the developer 'Ed1s0nZ' as China-based and linked to entities and programs associated with China's Ministry of State Security, raising concern about possible adoption by Chinese state-sponsored groups.
Amazon's CTI team and Team Cymru reported active use of CyberStrikeAI against Fortinet FortiGate appliances, including observed infrastructure, a CyberStrikeAI banner on an exposed host, and NetFlow communications with FortiGate targets.
Intrinsec reported identifying 48 command-and-control domains associated with AuraStealer from analysis of more than 200 VirusTotal samples, documenting active campaigns and infrastructure patterns.
The OpenClaw team released a fix in under 24 hours for the newly disclosed vulnerability and urged users to update to version 2026.2.25 or later.
Oasis Security reported a high-severity OpenClaw vulnerability that let a malicious website silently hijack a local AI agent through improperly trusted localhost WebSocket connections, without plug-ins or user interaction.
Lovable said it performs a security scan before publishing apps but expects users to implement recommended fixes themselves, a response that drew criticism after the disclosed vulnerabilities and data leak.
The vulnerable Lovable-hosted app led to a data leak affecting more than 18,000 users, with exposed access potentially enabling retrieval of user records, account deletion, bulk email abuse, and access to sensitive PII.
Security researcher and entrepreneur Taimur Khan identified 16 vulnerabilities, including six critical issues, in a Lovable-hosted application with more than 100,000 views.
Researchers observed limited CyberStrikeAI deployment until early 2026, followed by rapid growth in January and February 2026 as threat actors increasingly used it to target Fortinet FortiGate devices at scale.
The open-source AI-enabled offensive tool CyberStrikeAI was first made available on GitHub in November 2025, providing orchestration and automation features for offensive operations.
In October 2025, threat actors used a TikTok-based ClickFix social-engineering campaign to trick users into running an elevated PowerShell command that downloaded and executed AuraStealer.
Starting in July 2025, AuraStealer was promoted on multiple underground forums as a subscription-based stealer operated by Russian-speaking developers.
AuraStealer, a new information-stealing malware family, emerged in mid-2025 and began positioning itself as a competitor to other stealers in the cybercrime market.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.