Artificial intelligence has become both a primary tool for cyber attackers and a significant target for their operations, according to a recent report by CrowdStrike. The cybersecurity firm's analysis, covering the year leading up to June, indicates a substantial increase in AI-driven malicious activity, with AI agents generating more than twice the number of potentially malicious signals compared to human-triggered incidents.
CrowdStrike's threat hunting teams and systems processed an average of 14 million detection leads daily, which resulted in approximately 36,000 customer alerts over the twelve-month period. Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, noted that AI agent-driven behaviors have significantly surpassed human triggers, underscoring the widespread use of AI in cyberattacks.
The report highlights that AI-enabled malicious activity surged by 89% in the past year. Attackers are leveraging frontier AI models to identify vulnerabilities and develop resources such as AI-generated scripts, payloads, and commands, enhancing their efficiency and effectiveness. This technology also enables threat groups to devise more sophisticated automated attacks and amplify their impact by manipulating, disrupting, or sabotaging AI systems and data.
A particularly concerning finding is the speed at which vulnerabilities are being weaponized. The report states that 88% of vulnerabilities were weaponized through AI within 48 hours. This rapid exploitation renders the traditional 30-day patch window obsolete, forcing organizations to adopt a new baseline patch cycle of 24 to 48 hours.
The expanding AI ecosystem has also emerged as a new battleground for software supply chain attacks. As an example, the report cited the TeamPCP threat cluster, which compromised over 300 software dependencies in a single day during the first half of the year.
Meyers emphasized that the AI tools being implemented globally by enterprises are simultaneously creating an extended and often under-defended attack surface. He warned that many organizations do not yet perceive AI as both a weapon and a target, and consequently, have not adequately secured or established proper safeguards around the AI tools they use. The attack surface is expected to continue growing with the proliferation of agentic systems, AI application integrations, and dependency managers for AI agents. Securing AI, Meyers concluded, is absolutely critical.






