How did a Chinese-speaking hacker use Strix, Cairn, Hermes, and AI models to conduct largely autonomous attacks on online retailers in SepteAI-generated illustration; not an image of the attacker’s infrastructure or an affected retailer.
AI 提示詞
Create a landscape editorial hero image for this Studio Global article: How did a Chinese-speaking hacker use Strix, Cairn, Hermes, and AI models to conduct largely autonomous attacks on online retailers in Septe. Article summary: A Chinese-speaking operator reportedly used open-source AI agents to attack online retailers with little day-to-day supervision, stealing more than 600,000 payment-card records. The strongest documented count is **105 at. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
openai.com
一台意外暴露於公網的攻擊籌備伺服器,讓研究人員得以追查這起針對網路零售商的 AI 輔助攻擊。資安公司 Gambit Security 指出,操作者使用中文,並讓三套開源 AI 代理工具執行幾乎無須全程看管的工作;但伺服器上的工具與提示指令也顯示,背後仍有人在指揮。使用中文不足以判定操作者的國籍。35
三套工具如何分工?
Strix 搜尋漏洞,Cairn 嘗試利用漏洞取得存取權限,Hermes 則啟動、協調入侵工作,並讓操作者調整方向。報導指出,這套流程使用的 AI 模型包括 DeepSeek、Kimi,以及較舊版本的 Claude。取得系統存取權後,攻擊流程還會在結帳頁植入側錄程式,試圖擷取顧客輸入的付款資料。134