AI Is Both a Cyber Weapon and a Massive Target, CrowdStrike Warns
CrowdStrike said AI-enabled adversaries used machine-speed exploits and supply-chain attacks, with 48,200 vulnerabilities registered in 2025.
- CrowdStrike's annual Threat Hunting Report reveals attacks by AI-enabled adversaries surged 89 percent in 2025, positioning AI as a tool, target, and force multiplier for threat actors.
- "AI is both the weapon and the target," said CrowdStrike counter adversary division senior VP Adam Meyers, noting adversaries use frontier AI models to develop attack resources and exploit enterprise AI infrastructure.
- North Korean crew Famous Chollima "demonstrated the most advanced AI usage" in AI-focused development environments, while financially motivated crew Altered Spider compromised more than 300 software dependencies in one day; 88 percent of public proof-of-concept exploitations occurred within 48 hours of release.
- The traditional 30-day patch window is now "completely obsolete," forcing organizations onto 24 to 48-hour cycles as CrowdStrike's threat hunting team tracks AI agent-triggered leads at 2.5 times the human-triggered rate.
- In 2025, 48,200 CVEs were registered; 2026 has already reached 43,000 as of last week with June alone seeing more than 7,600 bugs, positioning AI tools as the next software supply chain battleground.
18 Articles
18 Articles
CrowdStrike: AI is now both the weapon and the target in cyberattacks
While AI is supposed to help defenders, it’s now creating more than twice as much noise as human-triggered incidents CrowdStrike detects as potentially malicious. The company’s threat hunting team and systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts during the one-year period ending in June. “AI agent-driven behaviors have surged past human triggers,” said Adam Meyers, senior vice presiden…
AI is 'both the weapon and the target' in latest wave of cyberattacks
AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal gangs and nation states using AI throughout the attack chain. Attackers are also targeting organizations' AI infrastructure and poisoning popular software packages to compromise their users. "AI is both the weapon and the target," …
Palo Alto Networks at Black Hat: How AI erased the 50-day patch window
Data released at this week’s Black Hat security conference suggests the era of manual zero-day hunting and 50-day patch windows is coming to an end. This is a double-edged sword for security professionals: Vulnerabilities can now be found at machine speed, perhaps bringing the discovery time eventually to zero, but it also means that AI-driven threats require autonomous operations to protect the organization. At the show, Palo Alto Networks unve…
Hackers Now Exploit Software Flaws Within 24 Hours — and AI Is Making Their Job Easier
The window between a vulnerability going public and the first real-world attack has almost disappeared. CrowdStrike’s 2026 Threat Hunting Report, covering the first half of the year, found that 88 percent of CVEs with published proof-of-concept exploits were used in active attacks within 48 hours. China-linked threat groups, including VAULT PANDA and GENESIS PANDA, have reached 24-hour turnaround on critical web application vulnerabilities — fas…
Coverage Details
Bias Distribution
- 75% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium















