ThinkPatternGet the app
Story
TECHNOLOGY · SEP 3, 2025

Cybercriminals Use Hexstrike-AI to Automate Citrix Software Exploits

Cybercriminals are using the AI-powered tool Hexstrike-AI to automate the exploitation of critical vulnerabilities in Citrix NetScaler software, reducing attack times to under 10 minutes.

Cybercriminals are utilizing Hexstrike-AI, an open-source agentic AI tool originally designed for red teaming, to rapidly automate attacks against Citrix NetScaler ADC and Gateway instances. By employing an Intelligent Decision Engine and a suite of over 150 cybersecurity tools, the tool can reduce the time required to exploit specific vulnerabilities from days or weeks to less than 10 minutes.

Check Point Research identified that attackers are using the tool to target CVE-2025-7775, CVE-2025-7776, and CVE-2025-8424. Hexstrike-AI simplifies complex processes such as authentication bypasses and memory operation analysis, which allows attackers to achieve unauthenticated remote code execution and deploy webshells.

Check Point Research warned that CVE-2025-7775 is already being exploited in the wild and expects attack volumes to rise as the gap between vulnerability disclosure and mass exploitation narrows.


Reported across 4 outlets
Actors
Citrix Systems

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play