A hacking crew's exploit notes were written by AI — and that should worry you more than the hack itself

Cisco Talos caught a Chinese-speaking group using AI to write its playbooks against 170,000 targets. The scary part isn't the bugs — it's that all…

Aliteq
Lena Fischer · AI & Local Compute Editor

What Talos actually found

UAT-10147 is a financially motivated, Chinese-speaking group running SEO fraud and data theft campaigns since early 2026.

What Talos actually found

An exposed directory revealed a target list of roughly 170,000 URLs, split into 17 files of about 10,000 each for operational efficiency.

What Talos actually found

Targets span government, education, media, technology and gaming sectors, with compromised servers found in Brazil, Bolivia, China, Canada and Vietnam.

What Talos actually found

The group used AI tools — PentestGPT for scanning and exploit execution, DeepAudit for source code vulnerability review, and AI-assisted ysoserial payload generation with matching AI-written…

What Talos actually found

Every CVE Talos observed being exploited is old — the newest dates to 2022, several go back to 2015 and 2010 — and all have long-available patches.

Aliteq

Read the full story

A hacking crew's exploit notes were written by AI — and that should worry you more than the hack itself

Read the full story on Aliteq