“AI Automates Hacking Too”... Oasis Security Reveals Signs of Attacks Targeting Domestic Universities

General News

Summary

Oasis Security says it identified an AI-driven attack framework called Hephaestus that automates reconnaissance, exploitation, persistence, lateral movement, and credential collection. The company reports that the framework is based on Anthropic Claude and uses separate agent roles to manage each phase of the attack chain. Its analysis also points to real-world targeting of government and education institutions in Indonesia, Bangladesh, and South Korea. The report highlights web shells, SQL injection, SSRF, and other chained exploits, along with signs of credential selling and malware-related monetization. The story underscores how generative AI is moving beyond defense support and into offensive cyber operations.

Classifications

industries
HealthTech
applications
AI & Machine learning

AskAI Classifications

Labels
Identity and Access Management (IAM) Cybersecurity Software Cloud Security

Linked Companies

Oasis Security
$1M to $5M