CrowdStrike Warns AI Adoption Is Creating Underdefended Attack Surfaces
内容摘要
Hackers are shrinking the time between a software flaw becoming public and a real attack to mere hours, and artificial intelligence is helping them move even faster, according to CrowdStrike's new 2026 Threat Hunting Report. The cybersecurity company said AI has become both a target and a weapon for attackers. Threat groups are using AI to generate malicious code, automate parts of their operations, abuse enterprise AI systems, and target the software supply chains that many companies rely on. One campaign highlighted by CrowdStrike sent nearly 200,000 requests to an AI model service in just two minutes, demonstrating how quickly attackers can abuse enterprise AI infrastructure. Adam Meyers, head of counter adversary operations at CrowdStrike, said: AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend. CrowdStrike also found that AI agent-triggered detection leads are appearing at 2.5 times the rate of human-triggered leads. During the first half of 2026, 88% of the vulnerability exploitation observed by CrowdStrike involving public proof-of-concept code occurred within 48 hours of the code's release. China-linked groups VAULT PANDA and GENESIS PANDA moved even faster, launching deliberate attacks within 24 hours of disclosure. Attackers are increasingly abusing legitimate authentication systems, cloud identities, and SaaS applications instead of relying on traditional malware. Vishing intrusions doubled during the first half of 2026, while monthly device-code phishing attempts increased 15-fold. Cloud-focused cybercrime activity surged 171%.
觉得这篇分析有用?
每周收到3-5条AI基础设施关键信号 →
💬 评论 (0)