ARTEX AI Pentesting Tool Exploited in Targeted Attacks on South Korean Financial Institutions
CrowdStrike Intelligence reports campaign using AI penetration testing tool for data exfiltration

Key Takeaways
- A targeted campaign against South Korean financial firms used the AI pentesting tool ARTEX between late September and early October 2026.
- CrowdStrike Intelligence attributed the activity, which resulted in data exfiltration.
- The exact threat actor, initial access method, and full exploitation chain have not been publicly confirmed.
Related Security News

FBI Arrests Suspected ShinyHunters Member Following Agency System Breach
The FBI arrested a suspect believed to be a member of the ShinyHunters extortion group, who is alleged to be involved in a recent breach of FBI systems. Director Kash Patel confirmed the arrest on Friday, marking a continued law enforcement effort to disrupt the group's operations.

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild to Deploy Webshells and Cryptominers
Threat actors are exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform. One vulnerability is rated critical severity and another medium severity. The exploitation has been observed in the wild and is being used to deploy webshells for persistent access and cryptocurrency miners for monetization. No patches are currently available, and the vulnerabilities remain unpatched. Affected organizations using AhsayCBS for backup management are at risk of persistent compromise and resource misuse.



