Three Open-Source AI Tools Let One Person Breach 27 Companies for $25 Each. The Total Take Was 600,000 Credit Cards.
Security firm Gambit Security traced a campaign that chained three open-source AI agent tools — Strix, Cairn and Hermes — into a fully automated pipeline that breached at least 27 companies between 10-15 September 2026, deployed skimmers on more than 100 websites, and stole over 600,000 unexpired credit card records, concentrated in just two of the compromised organizations. The average cost per target was $25.46, drawn from the operator's own logs across 101 completed scans. Attribution rests on Chinese-language commands and a self-chosen persona, not a confirmed identity.
ByDrafterDaily Editorial
Published
Read8 min
TechnologyAI
Questions
Frequently asked
3 answers
An operator chained three separate open-source AI agent tools — Strix for scanning and vulnerability discovery, Cairn for automated exploitation, and Hermes for orchestration and tactical decisions — into one pipeline that ran reconnaissance through skimmer deployment with no human technical operator directing each step.
Brussels Is About to Regulate AWS and Azure Without Their Passing the Size Test. Here's the Test It Used Instead.
The Commission's preliminary view says AWS and Azure miss the DMA's numerical thresholds but qualify on lock-in, switching costs and AI demand. Bloomberg reports a November designation, still a draft.
arXiv Now Caps Every Submitter at Two Papers a Month. The Cap Targets Moderator Workload, Not Paper Quality.
arXiv received a record 40,363 submissions in September 2026. Its new cap of two a month per submitter limits one behaviour, and the numbers to size it have not been published.
Citrix's Two 9.5-Rated NetScaler Bugs Were Exploited Before a Patch Existed. Upgrading Is Necessary, and Not Sufficient.
CVE-2026-88771 and CVE-2026-88772 were under attack before Citrix shipped fixes on 27 September. There is no workaround, and patching does not remove an attacker who is already inside.