{"slug": "crowdstrike-ai-is-now-both-the-weapon-and-the-target-in-cyberattacks", "title": "CrowdStrike: AI is now both the weapon and the target in cyberattacks", "summary": "CrowdStrike reports that AI-driven cyberattacks have surged 89% in the past year, with AI now serving as both a weapon and a target, according to its annual threat hunting report. The company's systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts, and 88% of vulnerabilities were weaponized through AI within 48 hours. Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, said AI agent-driven behaviors have surpassed human triggers, creating an extended attack surface that demands securing AI.", "body_md": "# CrowdStrike: AI is now both the weapon and the target in cyberattacks\n\nWhile AI is supposed to help defenders, it’s now creating more than twice as much noise as human-triggered incidents CrowdStrike detects as potentially malicious. The company’s threat hunting team and systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts during the one-year period ending in June.\n\n“AI agent-driven behaviors have surged past human triggers,” said Adam Meyers, senior vice president of counter adversary operations at CrowdStrike. “AI has driven the detections significantly above what humans are causing, and this gives you a sense of how frequently AI is being used, and really just that it’s being used everywhere.”\n\nThe threat posed by AI showed up incessantly during the past year, sparking alarming shifts and heightened targeting across software defects, open-source supply chains and AI tools themselves — all of which create greater difficulties for defenders, CrowdStrike said in its [annual threat hunting report](https://www.crowdstrike.com/en-us/resources/reports/threat-hunting-report/).\n\n“The AI tools that are being implemented by every enterprise across the globe right now are also creating an extended attack surface,” Meyers said during a press briefing.\n\n“AI is now a tool, a target, and a force multiplier for adversaries,” researchers wrote in the report, adding that AI-enabled malicious activity surged 89% during the past year as attackers used the technology to scale operations, hasten tradecraft and target AI infrastructure.\n\nAttackers are using frontier AI models to uncover vulnerabilities and develop resources, including AI-generated scripts, payloads and commands that increase their effectiveness and efficiency. The technology also allows threat groups to design more creative ways to run automated attacks and boost impact by manipulating, interrupting or sabotaging AI systems and data.\n\n“AI is both the weapon and the target,” Meyers said.\n\nMost organizations don’t view it as such, and thus far haven’t secured or put proper guardrails around the AI tools they use or address the ways attackers can use AI against them, he added.\n\nAI’s mark on vulnerabilities is particularly concerning, as reflected by what Meyers described as “one of the scarier stats” in this year’s report: 88% of vulnerabilities were weaponized through AI within 48 hours.\n\n“This is creating a rich ecosystem of vulnerabilities for attackers to use against various systems,” he said. It also renders the 30-day patch window obsolete, forcing organizations to struggle under a new baseline patch cycle of 24 to 48 hours, according to Meyers.\n\nThe AI ecosystem also became the next software supply chain battleground during the past year, as evidenced by [TeamPCP’s rampage through open-source software](https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/) in the first half of this year.\n\nThe threat cluster compromised more than 300 software dependencies in one day, Meyers said.\n\nAI tools are already in the crosshairs and the attack surface will continue to grow as agentic systems, AI application integrations and dependency managers for AI agents proliferate, the report concluded.\n\n“The same AI tools driving modern businesses are creating under-defended attack surfaces that adversaries are exploiting,” Meyers said. “We have to secure AI. This is absolutely critical.”", "url": "https://wpnews.pro/news/crowdstrike-ai-is-now-both-the-weapon-and-the-target-in-cyberattacks", "canonical_source": "https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/", "published_at": "2026-08-03 07:01:00+00:00", "updated_at": "2026-08-03 07:11:06.259093+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy"], "entities": ["CrowdStrike", "Adam Meyers", "TeamPCP"], "alternates": {"html": "https://wpnews.pro/news/crowdstrike-ai-is-now-both-the-weapon-and-the-target-in-cyberattacks", "markdown": "https://wpnews.pro/news/crowdstrike-ai-is-now-both-the-weapon-and-the-target-in-cyberattacks.md", "text": "https://wpnews.pro/news/crowdstrike-ai-is-now-both-the-weapon-and-the-target-in-cyberattacks.txt", "jsonld": "https://wpnews.pro/news/crowdstrike-ai-is-now-both-the-weapon-and-the-target-in-cyberattacks.jsonld"}}