Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ai-enabled-threat-activitycredential-stealer-activitythreat-infrastructure-trackingai-platform-security

AI-Enabled Threats and Security Failures Across Edge Devices, AI Agents, and Infostealer Campaigns

Updated 3mo agoFirst seen Mar 3, 20264 sources

Threat actors are increasingly operationalizing AI and automation to scale attacks and exploit weak controls across both enterprise and consumer environments. An open-source offensive platform dubbed CyberStrikeAI—a Go-based “AI-native security testing” framework integrating 100+ tools—was observed in infrastructure used to target Fortinet FortiGate edge devices at scale; researchers linked activity to an IP (212.11.64.250) exposing a CyberStrikeAI banner and to scanning/communications patterns consistent with mass exploitation. Separately, a newly disclosed and rapidly patched OpenClaw vulnerability showed how AI agent tooling can be hijacked: researchers reported that a malicious website could take over a developer’s locally running agent due to inadequate trust-boundary validation, prompting urgent upgrades to OpenClaw v2026.2.25+. In parallel, a “vibe-coding” hosted app on the Lovable platform leaked data impacting 18,000+ users after a researcher found 16 flaws (six critical) tied to mis-implemented backend controls (including missing/incorrect row-level security in Supabase), enabling unauthorized access to records and actions like bulk email and account deletion.

Criminal monetization also continues to evolve beyond AI-agent risks. AuraStealer, a Russian-language infostealer positioned as a successor/competitor after Lumma disruptions, was advertised on multiple underground forums and is supported by a sizable C2 footprint; analysis of 200+ samples identified 48 C2 domains, with operators abusing low-cost TLDs (e.g., .shop, .cfd) and using Cloudflare as a reverse proxy to mask origin infrastructure. Broader reporting and commentary reinforced that identity and access failures remain a dominant breach driver and that AI adoption is expanding the attack surface via over-privileged agents and “shadow AI,” while ransomware operators increasingly target recovery paths (including backups) and dwell to corrupt restore points. Several items in the set were non-incident thought leadership or workforce content (skills gap, jobs listings, awards, and general AI security tips) and did not add event-specific technical details beyond high-level risk framing.

Share:
AI-Enabled Threats and Security Failures Across Edge Devices, AI Agents, and Infostealer Campaigns
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
Mar 3, 20264mo ago

Report links CyberStrikeAI developer to Chinese state interests

The CyberStrikeAI report described the developer 'Ed1s0nZ' as China-based and linked to entities and programs associated with China's Ministry of State Security, raising concern about possible adoption by Chinese state-sponsored groups.

Researchers report CyberStrikeAI used to target FortiGate devices

Amazon's CTI team and Team Cymru reported active use of CyberStrikeAI against Fortinet FortiGate appliances, including observed infrastructure, a CyberStrikeAI banner on an exposed host, and NetFlow communications with FortiGate targets.

Intrinsec links 48 C2 domains to AuraStealer campaigns

Intrinsec reported identifying 48 command-and-control domains associated with AuraStealer from analysis of more than 200 VirusTotal samples, documenting active campaigns and infrastructure patterns.

Mar 2, 20264mo ago

OpenClaw patches critical AI agent hijack vulnerability

The OpenClaw team released a fix in under 24 hours for the newly disclosed vulnerability and urged users to update to version 2026.2.25 or later.

Oasis Security discloses critical OpenClaw localhost flaw

Oasis Security reported a high-severity OpenClaw vulnerability that let a malicious website silently hijack a local AI agent through improperly trusted localhost WebSocket connections, without plug-ins or user interaction.

Lovable responds to criticism over app security model

Lovable said it performs a security scan before publishing apps but expects users to implement recommended fixes themselves, a response that drew criticism after the disclosed vulnerabilities and data leak.

Lovable app data leak exposed more than 18,000 users

The vulnerable Lovable-hosted app led to a data leak affecting more than 18,000 users, with exposed access potentially enabling retrieval of user records, account deletion, bulk email abuse, and access to sensitive PII.

Researcher finds 16 flaws in Lovable-hosted app

Security researcher and entrepreneur Taimur Khan identified 16 vulnerabilities, including six critical issues, in a Lovable-hosted application with more than 100,000 views.

Jan 15, 20265mo ago

CyberStrikeAI use against FortiGate grows rapidly

Researchers observed limited CyberStrikeAI deployment until early 2026, followed by rapid growth in January and February 2026 as threat actors increasingly used it to target Fortinet FortiGate devices at scale.

Nov 1, 20258mo ago

CyberStrikeAI repository created on GitHub

The open-source AI-enabled offensive tool CyberStrikeAI was first made available on GitHub in November 2025, providing orchestration and automation features for offensive operations.

Oct 1, 20259mo ago

TikTok ClickFix campaign distributes AuraStealer

In October 2025, threat actors used a TikTok-based ClickFix social-engineering campaign to trick users into running an elevated PowerShell command that downloaded and executed AuraStealer.

Jul 1, 20251y ago

AuraStealer advertised on underground forums

Starting in July 2025, AuraStealer was promoted on multiple underground forums as a subscription-based stealer operated by Russian-speaking developers.

Jun 15, 20251y ago

AuraStealer emerges in underground malware ecosystem

AuraStealer, a new information-stealing malware family, emerged in mid-2025 and began positioning itself as a competitor to other stealers in the cybercrime market.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

42 LINKEDOpen in app
Affected products
11 linked
FortigateKeepassTelegramWindowsSpotifyBitwardenDiscordPowershellTiktokSteamSteam
Organizations
16 linked
Amazon Web ServicesTeam CymruKnownsecFortinetTrend MicroShutterstockThe RegisterCequence SecurityKoi SecuritySectigoVirustotalCloudflareSupabaseOasis SecurityLovableIntrinsec
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.