Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Europe’s AI labeling and transparency rules are now in effect

    August 3, 2026

    Chinese Actor Weaponizes Deepseek AI Agent Against Security Firm

    August 3, 2026

    Bernstein warns Clarity Act failure could spark another crypto selloff

    August 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Europe’s AI labeling and transparency rules are now in effect
    • Chinese Actor Weaponizes Deepseek AI Agent Against Security Firm
    • Bernstein warns Clarity Act failure could spark another crypto selloff
    • Ike Theriot Helps Prepare Astronauts to Work on the Moon 
    • Deep-sea snails and mussels in Indian and Pacific Oceans contain microplastics, study finds
    • Your Right to Know: Campaign finance site a big improvement
    • The Guardian view on funerals: the law must change following Robert Bush’s crimes | Editorial
    • Are AI companies scanning and destroying millions of books, including rare titles?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Technology

    AI is both a cyber weapon and a massive target, CrowdStrike warns

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 3, 2026 Technology No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Elyse Betters Picaro / ZDNET

    Follow ZDNET: Add us as a preferred source on Google.


    ZDNET’s key takeaways

    • CrowdStrike warns AI is both a target and a weapon.
    • LLMJacking made nearly 200,000 API calls in two minutes.
    • Malicious AI exploits flaws faster than defenders can patch them.

    Artificial intelligence is increasingly “an adversary tool and target,” researchers said, forcing businesses to rethink their defensive strategies in light of attack signals far outstripping what cybersecurity experts can manually handle. 

    According to CrowdStrike’s 2026 Threat Hunting Report, published on Monday, the same AI models, tools, and workflows that are giving businesses growth and productivity opportunities are being weaponized by cybercriminals in droves. 

    Also: How Google used AI agents to find and fix 1,072 Chrome security bugs – in 60 days

    As corporate networks expand, endpoint devices are added, and new large language models (LLMs) are deployed to handle various workloads, organizations are also unwittingly creating larger “undefended” attack surfaces that can be exploited to steal data, obtain AI model access, conduct surveillance, and potentially even harvest computing power for their own ends. 

    AI: The new weapon and target

    “AI is not just the tool or weapon that is being used, but it is also the attack surface,” Adam Meyers, head of threat intel at CrowdStrike, commented. “We’re seeing threat actors really adopt AI at the same speed that everybody else is.”

    CrowdStrike’s report said that the widespread adoption of artificial intelligence (much of it new and unproven) is increasing the sheer volume of signals that defenders have to sort through. 

    Also: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it

    There are now 2.5 times as many AI agent-triggered leads for the firm’s threat hunters to examine as there are manually driven leads, which CrowdStrike said “makes it more difficult for defenders to distinguish malicious activity from expected AI-driven behavior.”

    Suspicious alerts and signals underscore AI-driven activity in the criminal world — and the rapid speeds at which attacks are now being conducted. CrowdStrike gave a number of examples, including:

    • Famous Chollima: A Democratic People’s Republic of Korea (DPRK)-associated group is actively weaponizing trusted AI environments and tools to try to gain entry to companies working in cryptocurrency and the blockchain, using everything from AI-generated resumes to deepfake interviews. 
    • Cordial Spider, Snarky Spider: These groups use vishing to exfiltrate data from SaaS apps and compromise single sign-on accounts. In one case documented by the researchers, an attack shifted from account takeover to data theft in less than five minutes. 
    • LLMJacking: LLMJacking occurs when a threat actor gains access to keys or credentials used to access a company’s AI models. Armed with access to these LLMs — which are typically cloud-based — threat actors can then steal data and wreak havoc, such as forcing the model to perform malicious tasks or those that demand high compute power, creating massive bills for the victim. For example, CrowdStrike said that in one campaign, the victim’s LLM was used to generate close to 200,000 API requests in two minutes, “resulting in large-scale financial and operational impact.”

    AI is mostly used by cybercriminals today to generate phishing and vishing material, payloads, and commands, streamlining their attack chains and potentially creating more convincing phishing schemes designed for initial access. Meyers said these creations are becoming more bespoke, with custom tools generated by AI and LLMs to manage different defense scenarios.  

    Vulnerability windows vanish: More bad news for defenders

    Another concerning trend highlighted in the report is the shrinking window that human defenders — and their tools — have to respond between vulnerability discovery and exploitation.

    From January through June 2026, 88% of exploits detected by CrowdStrike were launched within 48 hours of a public proof-of-concept (PoC) code release. 

    Also: Not just OpenAI – Anthropic says Claude’s hacking spree ‘falls short of ideal behavior’

    Some threat groups, such as China’s Vault Panda and Genesis Panda, are keeping an even closer eye on new bugs: They developed working exploits for a critical vulnerability in a web application (React2Shell) within a day of disclosure. 

    In these situations, AI goes both ways. Two out of three recently disclosed LPE exploits, CopyFail and Fragnesia (Dirty Frag being the third), were discovered by AI-assisted research, and the report said “threat actors wasted no time incorporating them into active operations.”

    What does this mean for the enterprise and its cybersecurity teams? According to CrowdStrike, response times are going to become shorter and shorter — no doubt due in part to the weaponization of AI. 

    Also: Claude AI shared chats indexed by Google – see if your conversations were exposed

    “While this pattern predates the emergence of frontier AI models, the implementation of these systems is likely to compress vulnerability exploitation timelines by accelerating vulnerability discovery and exploit development,” the researchers said. “This could, in turn, increase the pressure on defenders already struggling to keep pace.”

    Your move

    AI can act as a shield, but as CrowdStrike’s research revealed, it can also be a weapon. 

    Also: Open weights vs. closed: An AI civil war’s afoot, and the stakes are existential

    With the pressure caused by AI, defenders will be hard-pressed to retain control and secure the networks and endpoints they are responsible for, and so the team recommended that businesses adopt the following practices:

    • Secure your AI applications and LLMs: With AI now embedded across multiple business environments, companies should enforce least-privilege principles, protect AI-related credentials, and monitor for suspicious LLM usage or cost spikes to reduce emerging business and operational risk. 
    • Identity is a primary attack surface: This issue existed before AI, but now, securing and verifying identities is even more important. Organizations should enforce phishing-resistant multifactor authentication, monitor access to corporate resources, and apply least privilege to human and non-human accounts.
    • Tackle cross-domain blind spots and secure the software supply chain: Digital blind spots in the supply chain and in your own networks can be exploited. Telemetry, behavioral detection and analysis software, frequent patch cycles, and threat intelligence can reduce the risk of compromise. 
    • Be proactive: AI weaponization, moving at a speed we can’t, is now forcing organizations to shift from a reactive to a proactive security stance. Investment, threat triage, and tackling the legacy security issues that threaten today’s networks should all be handled quickly. By reducing the attack surface, you’ll give your teams the breathing space to keep up.

    CrowdStrike Cyber massive Target warns Weapon
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Europe’s AI labeling and transparency rules are now in effect

    Bernstein warns Clarity Act failure could spark another crypto selloff

    Sequoia’s Shaun Maguire leads $1B round for nuclear startup Valar Atomics

    N-able warns of N-central auth bypass flaw exploited in attacks

    People Are Ghosting Long-Term Partners. Some Don’t Regret It

    Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Europe’s AI labeling and transparency rules are now in effect

    August 3, 2026

    Chinese Actor Weaponizes Deepseek AI Agent Against Security Firm

    August 3, 2026

    Bernstein warns Clarity Act failure could spark another crypto selloff

    August 3, 2026

    Ike Theriot Helps Prepare Astronauts to Work on the Moon 

    August 3, 2026
    Latest Posts

    A Russian Spy, Suddenly Cast Into the Spotlight, Flees Japan

    July 23, 2026

    Did Trump accidentally declassify proof Russia tried to help him win 2020 election?

    July 23, 2026

    Trump Puts Section 338 Tariffs on Canada as Greer Foreshadows New Global Duties

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Europe’s AI labeling and transparency rules are now in effect

    August 3, 2026

    Chinese Actor Weaponizes Deepseek AI Agent Against Security Firm

    August 3, 2026

    Bernstein warns Clarity Act failure could spark another crypto selloff

    August 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.