What is CVE-2026-33017?
CVE-2026-33017 is associated with a Chinese threat actor's exploitation campaign using Hermes, CyberStrikeAI, and SliverC2 tools, targeting AI-API resellers like derouter.ai and exposing 775 upstream API keys via an open endpoint. The campaign involves multiple C2 servers and infrastructure, posing risks primarily to exposed AI service configurations. Organizations should block the listed IOCs, apply security patches, and audit AI service exposure immediately.
Azərbaycanca: CVE-2026-33017 Çin mənşəli təhdid aktyorunun Hermes, CyberStrikeAI və SliverC2 alətlərindən istifadə edərək həyata keçirdiyi istismar kampaniyası ilə əlaqələndirilir. Bu kampaniya çərçivəsində derouter.ai kimi AI-API resellerlərində açıq endpointlər aşkarlanaraq 775 API açarı ifşa olunub. Təsirə məruz qalmamaq üçün təşkilatlar qeyd olunan İOC-ləri (göstəriciləri) bloklamalı, təhlükəsizlik yamalarını tətbiq etməli və AI xidmətlərinin konfiqurasiyalarını yoxlamalıdır.
Related CVEs
link basis: shared vendors: Claude, GPT, Tenable
FAQ2
Which threat tools were observed in the exploitation campaign associated with CVE-2026-33017?
This CVE is associated with a Chinese threat actor's campaign using Hermes, CyberStrikeAI, and SliverC2 tools.
What happened to AI-API resellers like derouter.ai during the CVE-2026-33017 campaign?
During the campaign, an open endpoint was discovered at AI-API resellers like derouter.ai, exposing 775 upstream API keys.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.