LIVE · cybersecurity feed
Live wire
vulnerability

CrowdStrike: AI is now both the weapon and the target in cyberattacks

AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first on CyberScoop.

zeroday.news · 4h ago

Artificial intelligence has become both a primary tool for cyber attackers and a significant target for their operations, according to a recent report by CrowdStrike. The cybersecurity firm's analysis, covering the year leading up to June, indicates a substantial increase in AI-driven malicious activity, with AI agents generating more than twice the number of potentially malicious signals compared to human-triggered incidents.

CrowdStrike's threat hunting teams and systems processed an average of 14 million detection leads daily, which resulted in approximately 36,000 customer alerts over the twelve-month period. Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, noted that AI agent-driven behaviors have significantly surpassed human triggers, underscoring the widespread use of AI in cyberattacks.

The report highlights that AI-enabled malicious activity surged by 89% in the past year. Attackers are leveraging frontier AI models to identify vulnerabilities and develop resources such as AI-generated scripts, payloads, and commands, enhancing their efficiency and effectiveness. This technology also enables threat groups to devise more sophisticated automated attacks and amplify their impact by manipulating, disrupting, or sabotaging AI systems and data.

A particularly concerning finding is the speed at which vulnerabilities are being weaponized. The report states that 88% of vulnerabilities were weaponized through AI within 48 hours. This rapid exploitation renders the traditional 30-day patch window obsolete, forcing organizations to adopt a new baseline patch cycle of 24 to 48 hours.

The expanding AI ecosystem has also emerged as a new battleground for software supply chain attacks. As an example, the report cited the TeamPCP threat cluster, which compromised over 300 software dependencies in a single day during the first half of the year.

Meyers emphasized that the AI tools being implemented globally by enterprises are simultaneously creating an extended and often under-defended attack surface. He warned that many organizations do not yet perceive AI as both a weapon and a target, and consequently, have not adequately secured or established proper safeguards around the AI tools they use. The attack surface is expected to continue growing with the proliferation of agentic systems, AI application integrations, and dependency managers for AI agents. Securing AI, Meyers concluded, is absolutely critical.

vulnerabilitypatchai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]

patch

AI is 'both the weapon and the target' in latest wave of cyberattacks

CrowdStrike tracks 89% surge in machine-assisted activity as patch windows shrink to 48 hours

security

A week in security (July 27 – August 2)

A list of topics we covered in the week of July 27 to August 2 of 2026

ai

OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems

OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]

breach

CareCloud Breach Exposes Medical and Financial Data of 345,000

CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, is finally notifying people impacted by a breach the firm first disclosed back in March. […]

ai

SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform

CALIFORNIA, USA, 2nd August 2026, CyberNewswire