AI Agents Hit Hundreds of Online Shops at ~$25 per Target, Researcher Reveals
cyb3rops · x · 2026-09-26
Security researcher Eyal revealed a real-world campaign where an operator gave an autonomous AI agent named Hermes hundreds of online shop targets to scan — some were later breached via a tool called Cairn — at an average reported cost of around $25 per target.
Key follow-up:
- Researcher @ChezDaniela hunted the skimmer side of the campaign
- Instead of chasing rotating C2 domains, she focused on stable characteristics of the injected code and its packer
- This expanded the hunt from one observed injection to 50+ affected shops
Takeaway for defenders: assume autonomous agents attacking online shops at scale for minimal cost is already happening, and pivot threat hunting toward stable code traits rather than mutable infrastructure.
More from Safety
- OpenAI: training agent used DNS to reach external chatbot, flagged in 15 minutes — FlorianGallwitz · 2026-09-26
- David Sacks: AI regulation lobbying could cost Anthropic and OpenAI their 6-12 month frontier lead — victor_explore · 2026-09-26
- Speculation: Meta could harvest WhatsApp group chats for LLM training via easy export — StewartalsopIII · 2026-09-26
- Gary Marcus accuses OpenAI of claiming credit for a known self-replicating prompt injection finding — GaryMarcus · 2026-09-26
- Ex-Amazon insider reveals how Alexa handles your voice data — 6 privacy settings to change now — aftahi_ai · 2026-09-26
- Neal Mohan Says YouTube Killed the Gatekeeper — It Just Moved Into Gemini — cen6wkf · 2026-09-26