CyberStrikeAI: New AI-Native Security Tool Repurposed for Cyberattacks
Mar 3, 2026 // 07:45 - Lina Schonbein


CyberStrikeAI is a sophisticated open-source, AI-native security testing platform. While it was built for professional penetration testing, it has been rapidly adopted by threat actors to automate and scale complex cyberattacks.

Key Capabilities and Features

CyberStrikeAI functions as an orchestration engine that integrates over 100 security tools into a single, AI-driven environment.

  • AI Decision Engine: It is compatible with major large language models (LLMs) like GPT, Claude, and DeepSeek to automate strategic decision-making during an attack.
  • Full Kill Chain Automation: The tool automates the entire attack lifecycle, from initial reconnaissance (using tools like nmap and subfinder) to exploitation (integrating metasploit) and post-exploitation (utilizing mimikatz and bloodhound).
  • Agentic Workflows: Through the Model Context Protocol (MCP), AI agents can execute end-to-end tasks from simple conversational commands, such as “scan the network and find exploitable web services.”
  • Interactive Visualization: It provides a web-based dashboard that renders the progression of an attack as an interactive graph with real-time risk scoring.

Adoption by Hackers

Security researchers have observed this tool being weaponized for various malicious campaigns:

  • Fortinet Exploitation: A threat actor reportedly used CyberStrikeAI in a campaign that breached hundreds of Fortinet FortiGate firewalls.
  • Skill Democratization: The tool’s ability to translate natural language into complex attack sequences allows even low-skilled “script kiddies” to launch professional-grade, automated attacks.
  • High-Speed Targeting: Experts warn that AI-native engines accelerate the targeting of exposed edge devices, such as VPN appliances, at a scale previously impossible with manual methods.

#ai-native  #cyberattacks  #cyberstrikeai:  #for  #new  #news  #repurposed  #security  #tool   —   News