AI-powered attack campaign compromises retailers cheaply
🔒 Research from Israeli security firm Gambit shows attackers used open-source AI tools to target 105 online retailers over five days, successfully compromising 27 of them. The campaign used tools named Strix, Cairn, and Hermes to find vulnerabilities, exploit them autonomously, and orchestrate operations. The attacker acquired AI model access via OpenRouter and spent roughly $7,005 over four weeks — about $25 per attack — while harvesting hundreds of thousands of credit card details and installing skimmer scripts.
