AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess. Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them. The post CrowdStrike: AI is now both the weapon and the target in cyberattacks appeared first on CyberScoop.

Artificial intelligence has become both a primary tool for cyber attackers and a significant target for their operations, according to a recent report by CrowdStrike. The cybersecurity firm's analysis, covering the year leading up to June, indicates a substantial increase in AI-driven malicious activity, with AI agents generating more than twice the number of potentially malicious signals compared to human-triggered incidents.
CrowdStrike's threat hunting teams and systems processed an average of 14 million detection leads daily, which resulted in approximately 36,000 customer alerts over the twelve-month period. Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, noted that AI agent-driven behaviors have significantly surpassed human triggers, underscoring the widespread use of AI in cyberattacks.
The report highlights that AI-enabled malicious activity surged by 89% in the past year. Attackers are leveraging frontier AI models to identify vulnerabilities and develop resources such as AI-generated scripts, payloads, and commands, enhancing their efficiency and effectiveness. This technology also enables threat groups to devise more sophisticated automated attacks and amplify their impact by manipulating, disrupting, or sabotaging AI systems and data.
A particularly concerning finding is the speed at which vulnerabilities are being weaponized. The report states that 88% of vulnerabilities were weaponized through AI within 48 hours. This rapid exploitation renders the traditional 30-day patch window obsolete, forcing organizations to adopt a new baseline patch cycle of 24 to 48 hours.
The expanding AI ecosystem has also emerged as a new battleground for software supply chain attacks. As an example, the report cited the TeamPCP threat cluster, which compromised over 300 software dependencies in a single day during the first half of the year.
Meyers emphasized that the AI tools being implemented globally by enterprises are simultaneously creating an extended and often under-defended attack surface. He warned that many organizations do not yet perceive AI as both a weapon and a target, and consequently, have not adequately secured or established proper safeguards around the AI tools they use. The attack surface is expected to continue growing with the proliferation of agentic systems, AI application integrations, and dependency managers for AI agents. Securing AI, Meyers concluded, is absolutely critical.

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 [





The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop.

Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.