Last seen September 2, 2025

Hexstrike-AI: LLM Orchestration Driving Real-World Zero-Day Exploits

Hexstrike-AI is an AI-powered orchestration framework designed to automate and accelerate zero-day exploitation, leveraging large language models to significantly reduce the time and skill required for complex attacks. Threat actors are actively discussing using Hexstrike-AI to target recently disclosed unauthenticated remote code execution and other critical vulnerabilities (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424) in Citrix NetScaler ADC and Gateway appliances, with observed webshell deployments.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Hexstrike-AI is an AI-powered orchestration framework designed to automate and accelerate zero-day exploitation, leveraging large language models to significantly reduce the time and skill required for complex attacks. Threat actors are actively discussing using Hexstrike-AI to target recently disclosed unauthenticated remote code execution and other critical vulnerabilities (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424) in Citrix NetScaler ADC and Gateway appliances, with observed webshell deployments.

Why This Matters

Publisher reporting describes a security event affecting Real. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether Real is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Sep 02, 2025 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

CitrixGateway appliancesHexstrike-AINetScaler ADCRemote Code ExecutionDay Exploits

Authoritative Intelligence

CVE CVE-2025-7775, CVE-2025-7776, CVE-2025-8424 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.

CVE-2025-7775: 1 public repository reference found.

swabird/CVE-2025-7775-PoC

Possible public PoC reference

GitHub repository for an AI tooling project

4 stars · Python

Open repository

A public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.

Timeline

  • Incident first seen
    Sep 02, 2025 05:30

    BugSkan first recorded this incident.

  • Hexstrike-AI: LLM Orchestration Driving Real-World Zero-Day Exploits - Check Point Blog
    Sep 02, 2025 05:30

    blog.checkpoint.com · Vulnerability

Sources

Hexstrike-AI: LLM Orchestration Driving Real-World Zero-Day Exploits - Check Point Blog

blog.checkpoint.com · Sep 02, 2025 05:30

Hexstrike-AI is an AI-powered orchestration framework designed to automate and accelerate zero-day exploitation, leveraging large language models to significantly reduce the time and skill required for complex attacks. Threat actors are actively discussing using Hexstrike-AI to target recently disclosed unauthenticated remote code execution and other critical vulnerabilities (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424) in Citrix NetScaler ADC and Gateway appliances, with observed webshell deployments.

Open publisher source

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence