Cisco Talos identified a financially motivated Chinese-speaking hacking group, tracked as UAT-10147, using AI-driven tools to compromise internet-facing Windows and Linux servers. The attackers used AI-generated guidance and tooling to refine exploits and automate post-compromise activity, relying heavily on publicly known vulnerabilities rather than novel techniques. A target list of roughly 170,000 URLs was found on the group's C2 infrastructure. Analysts warn AI is shrinking the window defenders have to detect and contain intrusions, pushing organizations toward pre-approved containment actions, exposure-based prioritization over raw CVSS scores, and greater automation in SOC triage.

5m read timeFrom csoonline.com
Post cover image

Questions this post answers

How is AI being used by hackers to attack internet-facing servers?

A financially motivated Chinese-speaking group tracked as UAT-10147 uses AI-generated operational guidance and tooling to refine exploits when they fail and to automate parts of post-compromise activity, according to Cisco Talos research. The group primarily exploits already-known, publicly disclosed vulnerabilities rather than novel ones, but AI lets it work through exposed Windows and Linux servers faster and with less specialist expertise, and a target list of about 170,000 URLs was found on its command-and-control infrastructure. Security teams tracking AI-accelerated exploitation trends can follow threat research like this on daily.dev.

Why should CVSS score alone not be used to prioritize vulnerability patching?

CVSS severity alone is an insufficient basis for prioritization because internet exposure and available exploit code can make a lower-scoring flaw more urgent than a higher-scoring one buried inside an internal network. Security teams should weigh exposure, exploit availability, and what systems or privileged identities an attacker could reach after compromise, and apply compensating controls like segmentation when immediate patching isn't possible. Teams rethinking patch prioritization beyond raw CVSS scores can find related analysis on daily.dev.

178 Impressions