{"slug": "crowdstrike-finds-ai-systems-under-direct-attack-as-exploit-windows-shrink", "title": "CrowdStrike finds AI systems under direct attack as exploit windows shrink", "summary": "CrowdStrike Holdings Inc.'s 2026 Threat Hunting Report finds AI systems are now direct targets of attackers, with exploit windows shrinking to under 48 hours in 88% of cases between January and June. The report, covering 290 named adversaries, shows AI model access techniques accounting for 16% of observed MITRE ATLAS techniques, and LLMjacking attacks hijacking corporate large language model access, including a May campaign that sent nearly 200,000 API requests in two minutes.", "body_md": "### CrowdStrike finds AI systems under direct attack as exploit windows shrink\n\nArtificial intelligence has become a target for attackers rather than only a tool they use, according to CrowdStrike Holdings Inc.’s “2026 Threat Hunting Report,” [released today](https://www.crowdstrike.com/en-us/resources/reports/threat-hunting-report/).\n\nThe annual report draws on observations from CrowdStrike’s OverWatch threat hunting team and intelligence analysts tracking more than 290 named adversaries over the 12 months to June 30. Previous editions counted only interactive, hands-on-keyboard intrusions. This year’s also folds in automated attacks, a methodology change CrowdStrike says gives a more accurate picture of how adversaries now operate.\n\nCrowdStrike now measures [the exploitation window](https://siliconangle.com/2026/03/25/adversaries-log-speed-strength-ai-fueled-attacks-cybersecurity-industry-playing-catch/) in hours rather than days. It counted the gap between a proof-of-concept exploit going public and attackers picking it up. Between January and June, that gap came in under 48 hours in 88% of cases, and the year before, zero-day exploitation had risen 42%.\n\nTwo China-nexus groups beat even that. React2Shell ([CVE-2025-55182](https://nvd.nist.gov/vuln/detail/CVE-2025-55182)), an unauthenticated remote code execution flaw in React Server Components and Next.js, was disclosed alongside patches on Dec. 3, 2025. Working exploit code appeared the next day. Vault Panda and Genesis Panda were attacking within 24 hours. OverWatch chased more than 800 hunting leads at more than 80 victims in the first four days.\n\nAI infrastructure itself is now being probed directly. AI model access techniques accounted for 16% of the MITRE ATLAS techniques CrowdStrike observed over the year. The company’s honeypot infrastructure captured one exploit payload carrying a malicious Model Context Protocol server configuration, built to read a parent process’s environment variables and send configuration data to an external webhook.\n\nCorporate large language model access is being hijacked outright, a practice the report calls LLMjacking. In a May campaign against a cloud provider’s foundation model service, a threat actor escalated a compromised identity to administrator privileges and submitted the use-case form required to unlock model access. It then sent nearly 200,000 application programming interface requests in an initial two-minute flood before throttling kicked in.\n\nAdversaries are using the technology as much as they are attacking it. Famous Chollima, the North Korean group behind large-scale IT worker infiltration, built entire fake companies with AI-generated websites, GitHub accounts and email infrastructure to support insider operations. AI agent-triggered detection leads now arrive at 2.5 times the rate of human-triggered leads, OverWatch said.\n\nSoftware registries remain the shortest path into [developer environments](https://siliconangle.com/2026/05/20/github-confirms-breach-3800-internal-repos-employee-installs-poisoned-vs-code-extension/). Malicious npm packages accounted for 87% of identified malicious software registry threats in the first half of 2026.\n\nStardust Chollima used stolen maintainer credentials to compromise the Axios npm package [in March](https://siliconangle.com/2026/03/31/hackers-compromise-popular-axios-javascript-library-hidden-malware/). In June it injected a malicious npm dependency into at least 131 Mastra AI framework packages. The way in was a Mastra employee: the group approached them on LinkedIn, then got them onto a video call and talked them into clicking a malicious link.\n\nInternet crime group Altered Spider works at a different scale. [Its malware self-propagates](https://siliconangle.com/2025/12/23/shai-hulud-malware-turns-developers-unwitting-distributors-npm-supply-chain-attacks/), taking stolen maintainer credentials and republishing infected packages on its own. In one day during its May campaigns, the group compromised more than 300 software dependencies. In March, it poisoned Git tags on the publicly available trivy-action GitHub Action, part of Aqua Security Software Ltd.’s Trivy scanner, so that any organization pulling the affected releases in an automated build ran credential-stealing malware inside its own pipeline.\n\nResearchers at Forcepoint LLC detailed that compromise [in May](https://siliconangle.com/2026/05/18/forcepoint-details-teampcp-supply-chain-attack-turned-litellm-credential-stealer/) and traced it to a group they called TeamPCP. CrowdStrike attributes the activity to Altered Spider.\n\n[Identity abuse](https://siliconangle.com/2026/03/30/identity-theft-becomes-new-perimeter-attackers-bypass-security-defenses/) rounds out the picture. Vishing intrusions in the first half of 2026 ran at twice the rate of the second half of 2025, following a 134% increase between 2024 and 2025. Cordial Spider and Snarky Spider used vishing calls to steer targets to spoofed single sign-on pages loaded on personal mobile devices, then moved into integrated software-as-a-service applications to exfiltrate data. In one incident, Snarky Spider went from account takeover to data theft in under five minutes. Monthly device code phishing attempts rose 15-fold over the past six months.\n\nCloud-conscious internet crime activity climbed 171% over the reporting period. In one case a threat actor hijacked cloud resources at a U.S. technology company across three parallel attack vectors, mining about $41,000 worth of Monero while altering instance settings to stop the victim reclaiming the compute.\n\nNot every intrusion arrived over a network. Between March and May, OverWatch disrupted close access operations in which China-nexus adversary Overcast Panda installed its FlowCloud backdoor on unattended laptops belonging to travelers inside China. The adversary booted the machines from removable media, writing the implant to disk outside the running operating system.\n\nOverall intrusion activity rose roughly 4%, well down on the [27% surge reported a year ago](https://siliconangle.com/2025/08/04/cloud-breaches-identity-hacks-explode-crowdstrikes-latest-threat-report/), though this year’s count includes automated attacks that earlier editions excluded. CrowdStrike attributed the plateau to adversaries putting time into fewer, more complex campaigns. Technology was the most targeted sector for the ninth consecutive year, while financial services and academic institutions recorded the largest increases, at 11% and 17%.\n\n“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” said Adam Meyers, head of counter adversary operations at CrowdStrike, in announcing the report. “The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary.”\n\n##### Photo: Robert Hof/SiliconANGLE\n\n# A message from John Furrier, co-founder of SiliconANGLE:\n\nSupport our mission to keep content open and free by engaging with theCUBE community. **Join theCUBE’s Alumni Trust Network**, where technology leaders connect, share intelligence and create opportunities.\n\n**15M+ viewers of theCUBE videos**, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.\n\n# Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links.\n\n**About SiliconANGLE Media**\n\n[SiliconANGLE](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552),\n\n[theCUBE Network](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da),\n\n[theCUBE Research](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f),\n\n[CUBE365](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6),\n\n[theCUBE AI](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683)and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.\n\nFounded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.", "url": "https://wpnews.pro/news/crowdstrike-finds-ai-systems-under-direct-attack-as-exploit-windows-shrink", "canonical_source": "https://siliconangle.com/2026/08/03/crowdstrike-finds-ai-systems-direct-attack-exploit-windows-shrink/", "published_at": "2026-08-03 04:01:34+00:00", "updated_at": "2026-08-03 04:23:06.046147+00:00", "lang": "en", "topics": ["ai-safety", "ai-infrastructure", "ai-policy"], "entities": ["CrowdStrike Holdings Inc.", "OverWatch", "MITRE ATLAS", "React2Shell", "Vault Panda", "Genesis Panda", "Famous Chollima", "Stardust Chollima"], "alternates": {"html": "https://wpnews.pro/news/crowdstrike-finds-ai-systems-under-direct-attack-as-exploit-windows-shrink", "markdown": "https://wpnews.pro/news/crowdstrike-finds-ai-systems-under-direct-attack-as-exploit-windows-shrink.md", "text": "https://wpnews.pro/news/crowdstrike-finds-ai-systems-under-direct-attack-as-exploit-windows-shrink.txt", "jsonld": "https://wpnews.pro/news/crowdstrike-finds-ai-systems-under-direct-attack-as-exploit-windows-shrink.jsonld"}}