CrowdStrike: AI is now both the weapon and the target in cyberattacks
While AI is supposed to help defenders, itβs now creating more than twice as much noise as human-triggered incidents CrowdStrike detects as potentially malicious. The companyβs threat hunting team and systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts during the one-year period ending in June.
βAI agent-driven behaviors have surged past human triggers,β said Adam Meyers, senior vice president of counter adversary operations at CrowdStrike. βAI has driven the detections significantly above what humans are causing, and this gives you a sense of how frequently AI is being used, and really just that itβs being used everywhere.β
The threat posed by AI showed up incessantly during the past year, sparking alarming shifts and heightened targeting across software defects, open-source supply chains and AI tools themselves β all of which create greater difficulties for defenders, CrowdStrike said in its annual threat hunting report.Β
βThe AI tools that are being implemented by every enterprise across the globe right now are also creating an extended attack surface,β Meyers said during a press briefing.Β
βAI is now a tool, a target, and a force multiplier for adversaries,β researchers wrote in the report, adding that AI-enabled malicious activity surged 89% during the past year as attackers used the technology to scale operations, hasten tradecraft and target AI infrastructure.
Attackers are using frontier AI models to uncover vulnerabilities and develop resources, including AI-generated scripts, payloads and commands that increase their effectiveness and efficiency. The technology also allows threat groups to design more creative ways to run automated attacks and boost impact by manipulating, interrupting or sabotaging AI systems and data.
βAI is both the weapon and the target,β Meyers said.Β
Most organizations donβt view it as such, and thus far havenβt secured or put proper guardrails around the AI tools they use or address the ways attackers can use AI against them, he added.Β
AIβs mark on vulnerabilities is particularly concerning, as reflected by what Meyers described as βone of the scarier statsβ in this yearβs report: 88% of vulnerabilities were weaponized through AI within 48 hours.Β
βThis is creating a rich ecosystem of vulnerabilities for attackers to use against various systems,β he said. It also renders the 30-day patch window obsolete, forcing organizations to struggle under a new baseline patch cycle of 24 to 48 hours, according to Meyers.
The AI ecosystem also became the next software supply chain battleground during the past year, as evidenced by TeamPCPβs rampage through open-source software in the first half of this year.Β
The threat cluster compromised more than 300 software dependencies in one day, Meyers said.Β
AI tools are already in the crosshairs and the attack surface will continue to grow as agentic systems, AI application integrations and dependency managers for AI agents proliferate, the report concluded.
βThe same AI tools driving modern businesses are creating under-defended attack surfaces that adversaries are exploiting,β Meyers said. βWe have to secure AI. This is absolutely critical.β
The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first on CyberScoop.

