
What happened
Gambit Security investigated a seized attacker relay server and found three open-source AI tools — Hermes, Strix and Cairn — handled vulnerability hunting, intrusion, privilege escalation and data theft on their own.
Why it matters
Attackers only picked targets and gave short goals, so one firm could be attacked for hours at low cost — a barrier that once protected smaller companies appears to be falling.
What to watch
The findings are provisional, and many attack projects remain unexamined, so actual scale may be larger; watch whether the reported $25.46 average cost per scan holds as more logs are reviewed.
WHO IT HITSRetail IT and security teams running custom-built e-commerce systems are most exposed, since Gambit Security says the attackers deliberately favored stores on self-developed platforms over major EC platforms.
Summaries like this, in your inbox every morning.
Gambit Security's investigation began with an unusual asset: a relay server belonging to one of the attackers. From that vantage point the firm could watch how the campaign actually ran, and what it saw was not a human crew typing commands but a chain of open-source tools dividing labor. Strix scouted targets, Cairn pursued entry for hours on its own, and Hermes coordinated the job using a library of 121 skills. Human input was sparse — 1,951 prompts across 260 sessions, only a few instructions per target.
What makes the campaign distinctive is that the AI did not repeat one fixed attack. Cairn assessed each target's website and server state and built an attack path on the spot, so the vulnerabilities exploited varied widely by victim. In one documented case, a SQL injection flaw led to a database, one-time passwords were read to defeat multi-factor authentication, an admin panel was breached, a file-upload weakness allowed code execution, and the trail eventually reached a Magento database where encrypted credit card numbers could be decrypted. Targets were not random either: the attackers pulled shopping sites from access-ranking services, excluded those on major EC platforms, and prioritized stores running custom-built systems likely to carry unknown flaws.
The economics are the part Gambit Security calls more important than the attack's scale. The main tools are open source, and adding one more target costs only tens of dollars, while AI can work in parallel without tiring. Companies that once seemed too small to be worth attacking may now fall inside the attackers' reach — a shift that hinges on how far these low costs fall and how quickly defenders can respond to self-restoring malicious code. Gambit Security cautions that its report is a provisional finding, and with many attack projects still unexamined, the true scale and damage may prove larger than the numbers published so far.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
OpenAI published 722 math manuscripts in 372 result families to a public GitHub repo, drawn from about 4,000 p…

OpenAI's Chris Lehane told Japanese reporters that an unreleased model, GPT-5.6 Sol, chained vulnerabilities t…

GMO Pepabo said the remote MCP server for its Muumuu Domain byGMO Pepabo service was listed in Anthropic's Cla…

Google released EmbeddingGemma 2, its first natively multimodal open embedding model on the Gemma 4 architectu…

Between May and June 2026, OpenAI ran the ExploitGym cyber-capability benchmark on isolated agents allowed onl…

The Wikimedia Foundation said AI agents apparently run by OpenAI made unauthorized edits, tried to break into…
