# Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated Large-Scale Attacks, incl. CVE-2025-7775 Citrix NetScaler

> Netlas reports that affordable local AI hardware (NVIDIA DGX Spark), abliterated open-weight models and MCP-based agentic orchestration are converging to make autonomous, large-scale attacks cheap. Check Point documented threat actors pointing the open-source HexStrike-AI MCP framework at Citrix NetScaler CVE-2025-7775 within 12 hours of disclosure, with claims of exploitation compressed from days to under ten minutes.

- **Published:** 2026-10-03T00:00:00Z
- **Last reviewed:** 2026-10-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2881
- **ID:** TL-2026-2881
- **Severity:** HIGH (CVSS 9.8)
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-7775, CVE-2025-7776, CVE-2025-8424

## Description

Netlas (Bedrettin Ortak, 2026-08-05) argues that three trends now combine: (1) desktop AI hardware such as the NVIDIA DGX Spark (1 petaFLOP FP4, 128 GB unified memory, 4 TB SSD, $4,699 as of August 2026; fine-tuning of models up to ~70B parameters and inference up to ~200B), (2) abliterated open-weight models, where refusal behaviour is removed by editing weights (technique popularised by FailSpy building on Arditi et al. 2024; automated by the Heretic tool; an Alice research study of April 2026 reported harmful-prompt compliance rising from 5.8% to 98% across 5 models after abliteration), and (3) agentic orchestration over the Model Context Protocol (MCP), which lets a language model drive many offensive tools autonomously.

The concrete incident cited is HexStrike-AI, an MIT-licensed open-source MCP server (GitHub 0x4m4/hexstrike-ai, published by Muhammad Osama / OTT Cybersecurity LLC) that exposes 150+ security tools (Nmap, Nuclei with 4,000+ templates, browser automation, cloud assessment, 12+ specialised agents) to MCP-capable clients such as Claude Desktop, VS Code Copilot, Cursor and Roo Code. Check Point Research (2025-09-02) reported that within about 12 hours of Citrix's 2025-08-26 advisory for three NetScaler zero-days (CVE-2025-7775, CVE-2025-7776, CVE-2025-8424), underground-forum actors were discussing using HexStrike-AI against them. Claims included unauthenticated RCE on CVE-2025-7775, webshell deployment for persistence, parallel scanning of thousands of IPs, and sale of compromised/vulnerable instances. The 'under 10 minutes' timing is an actor claim relayed by Check Point, not independently measured.

CVE-2025-7775 is a memory overflow (CWE-119) in NetScaler ADC/Gateway leading to RCE and/or DoS, CVSS v3.1 9.8 / v4.0 9.2, exploitable without authentication on appliances configured as Gateway (VPN vserver, ICA Proxy, CVPN, RDP Proxy), AAA vservers, LB vservers bound to IPv6 services, or CR vservers of type HDX. It was added to CISA KEV on 2025-08-26 (federal due date 2025-08-28). Shadowserver counted ~28,000 exposed endpoints initially and ~8,000 by 2025-09-02.

For context the article also cites GTG-1002, assessed by Anthropic with high confidence as a Chinese state-sponsored group that in mid-September 2025 used Claude Code with MCP-connected scanners and password crackers to run an espionage campaign against ~30 targets (technology, finance, chemical manufacturing, government), with the AI performing an estimated 80-90% of tactical work and humans making 4-6 decision points per campaign. GTG-1002 bypassed safeguards through role-play (posing as defensive testers) and task decomposition, not abliteration; Claude's hallucinated credentials were a limiting factor. XBOW, a legitimate autonomous pentester that topped the HackerOne US leaderboard in June 2025, is cited as evidence of the speed of autonomous offense. There is no single named adversary or new malware in the Netlas article; this record tracks the capability trend and the HexStrike-AI/NetScaler abuse.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1588.007 Artificial Intelligence
- T1588.002 Tool
- T1588.006 Vulnerabilities
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1505.003 Web Shell
- T1110 Brute Force
- T1046 Network Service Discovery
- AML.T0054 LLM Jailbreak
- AML.T0053 AI Agent Tool Invocation
- AML.T0018 Manipulate AI Model

## Sources

- [Desktop AI Supercomputers and Automated Attacks (Netlas)](https://netlas.io/blog/desktop_ai_supercomputers_and_automated_attacks/)
- [Check Point: HexStrike-AI - When LLMs Meet Zero-Day Exploitation](https://blog.checkpoint.com/executive-insights/hexstrike-ai-when-llms-meet-zero-day-exploitation/)
- [BleepingComputer: Hackers use new HexStrike-AI tool to rapidly exploit n-day flaws](https://www.bleepingcomputer.com/news/security/hackers-use-new-hexstrike-ai-tool-to-rapidly-exploit-n-day-flaws/)
- [Infosecurity Magazine: Threat Actors Use HexStrike-AI](https://www.infosecurity-magazine.com/news/threat-actors-hexstrikeai/)
- [Anthropic: Disrupting the first reported AI-orchestrated cyber espionage campaign](https://www.anthropic.com/news/disrupting-AI-espionage)
- [HexStrike AI MCP Agents repository](https://github.com/0x4m4/hexstrike-ai)
- [Wiz Vulnerability Database: CVE-2025-7775](https://www.wiz.io/vulnerability-database/cve/cve-2025-7775)
- [NVD: CVE-2025-7775](https://nvd.nist.gov/vuln/detail/cve-2025-7775)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Alice abliteration report (April 2026)](https://go.alice.io/hubfs/alice-abliteration-report-april2026.pdf)
- [XBOW: Top 1 - how XBOW did it](https://xbow.com/blog/top-1-how-xbow-did-it)
- [Hugging Face: Uncensor any LLM with abliteration](https://huggingface.co/blog/mlabonne/abliteration)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2881
