New data tells a scary story about the impact of AI agents on cybersecurity. One of the first extensive cybersecurity reports since the rise of agents has arrived, and the results are as alarming as the industry expected. On August 3, cybersecurity giant CrowdStrike released its 2026 Threat Hunting Report, which found:
- Cloud-focused cybercrime increased 171% in one year
- AI agents set off 2.5 times more security alerts than people did
- 88% of known software flaws are now attacked within two days of public release, challenging the traditional 30-day patch window
"It used to be that the time when a vulnerability was released to when an exploit was available could be measured in months, if not years, and now it’s being measured in hours," Adam Meyers, CrowdStrike's senior vice president of intelligence, told The Deep View.
For enterprises dealing with the fallout from agentic-enabled cybersecurity attacks, there are several new realities they have to come to grips with: AI is not only a hacking tool, it's now a target: Attackers are going after model access, API keys, agent permissions, and development environments.** The AI ecosystem itself is a new supply chain battleground**: The weakest point may be open-source packages (especially npm), agent integrations, developer identities, and automated pipelines.Enterprise patching has to accelerate: Perhaps most of all, enterprises can't wait to patch software in long, regular cycles any more, but will have to move closer to real-time patching.
"It has gone from a manageable problem to a completely unmanageable problem," said Meyers, about the exploit timeframe, "and it’s going to require thinking about things differently, and changing behaviors."
Our Deeper View #
As 2026 has unfolded, it's become very clear across the tech industry that AI agents are transforming workflows so rapidly that it's taking time to assess the impacts. In cybersecurity, the CrowdStrike threat report has provided clarity around the dangers AI agents now pose by accelerating the exploit window and targeting trusted identities within an organization's AI supply chain as an easier path for break-ins than traditional hacking techniques. One bright spot is that when I asked Meyers how things went with Project Glasswing, where Anthropic worked with industry leaders, including CrowdStrike, to provide early access to its next-gen AI model, Mythos, so the industry could get a step ahead of bad actors. Meyers said both the industry and the AI lab learned a lot about how to collaborate and improve the situation more quickly going forward.