LIVE · cybersecurity feed
Live wire
patch

AI is 'both the weapon and the target' in latest wave of cyberattacks

CrowdStrike tracks 89% surge in machine-assisted activity as patch windows shrink to 48 hours

zeroday.news · 4h ago

Cybersecurity firm CrowdStrike reports an 89 percent increase in AI-enabled cyberattacks in 2025, noting that artificial intelligence is being utilized by adversaries as both a weapon and a target. The company's annual Threat Hunting Report indicates that both criminal organizations and state-sponsored groups are integrating AI across the entire attack chain. Attackers are also specifically targeting AI infrastructure and compromising popular software packages to affect users.

CrowdStrike's counter adversary division senior vice president, Adam Meyers, stated that AI represents a high-value attack surface increasingly exploited by threat actors. The firm's threat hunting team now identifies AI agent-triggered leads at 2.5 times the rate of human-triggered threats, a trend observed across government-backed and financially motivated groups.

Among the 290 adversary groups tracked by CrowdStrike, the North Korean group Famous Chollima, a sub-unit of the Lazarus Group, demonstrated the most advanced AI usage between the second half of 2025 and the first half of 2026. This group is known for creating entirely fake companies with AI-generated websites, GitHub accounts, and email infrastructure to support insider threat operations.

AI supply-chain compromise was identified as the second most common MITRE ATLAS technique for initial access. Famous Chollima's campaign targeting AI-focused development environments was cited as a sophisticated example of this technique. This included a supply-chain attack in January and February targeting cryptocurrency and blockchain companies, where trojanized repositories, primarily on GitHub, contained legitimate-looking project files alongside hidden malicious scripts. These scripts automatically executed commands, granting Famous Chollima access to developer environments.

Another Lazarus Group offshoot, tracked as Stardust Chollima or Sapphire Sleet, is suspected to be behind the March Axios supply chain attack. Amazon has also attributed four npm compromises over the past 18 months to the same North Korean crew.

Financially motivated groups are also leveraging AI. CrowdStrike tracks Altered Spider, also known as TeamPCP, which targeted developers' AI tools, compromising over 300 software dependencies in a single day. This group harvested credentials and secrets before moving into cloud environments for theft and extortion. Meyers noted that Altered Spider can compromise an endpoint in seconds and penetrate cloud environments within minutes, demonstrating rapid movement tied to software supply chains.

CrowdStrike also highlights that AI is accelerating the exploitation of newly disclosed vulnerabilities. From January to June, 88 percent of observed exploitation using public proof-of-concept (PoC) code occurred within 48 hours of the code's release. China-linked groups such as Vault Panda and Genesis Panda launched attacks even faster, within 24 hours of disclosure.

This rapid weaponization of vulnerabilities by AI is rendering the traditional 30-day patch window obsolete, shortening it to 24-hour or 48-hour cycles. Organizations are reportedly struggling to keep pace.

Concurrently, AI is proving highly effective at discovering new software bugs. In 2025, approximately 48,200 CVEs were registered. As of early August this year, 43,000 CVEs have already been recorded, nearing last year's total. June alone saw over 7,600 software bugs reported and tracked through CVEs, indicating a significant increase in the vulnerability ecosystem.

patchai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

CrowdStrike: AI is now both the weapon and the target in cyberattacks

AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first on CyberScoop.

security

A week in security (July 27 – August 2)

A list of topics we covered in the week of July 27 to August 2 of 2026

ai

OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems

OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]

vulnerability

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]

breach

CareCloud Breach Exposes Medical and Financial Data of 345,000

CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, is finally notifying people impacted by a breach the firm first disclosed back in March. […]

ai

SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform

CALIFORNIA, USA, 2nd August 2026, CyberNewswire