Tuesday, August 4, 2026

Report: Attackers using AI as weapon to target enterprise AI tools

Cyberattackers are using artificial intelligence to accelerate operations while exploiting security weaknesses created by the rapid adoption of enterprise AI tools, according to CrowdStrike’s “2026 Threat Hunting Report”.

“AI is the weapon and the target. We’ve seen that AI is being used by more and more threat actors and is a high value attack surface,” Adam Meyers, CrowdStrike’s head of counter adversary operations, said during the report’s launch.

“The AI tools being implemented by every enterprise across the globe now are creating the extended attack surface.”

The report, released Monday, Aug. 3, examined the activities of more than 290 adversaries worldwide, including 11 threat actors identified since the previous edition.

CrowdStrike said its Falcon platform detected 2.5 times more AI agent-driven activity on endpoints than human-driven activity during the first quarter of 2026.

The findings indicate that attackers are increasingly using AI to automate tasks previously performed manually, including generating scripts, payloads, and commands during cyberattacks.

Voice phishing, or vishing, also increased, with CrowdStrike recording twice as many attacks in the first half of 2026 as during the same period last year. AI can make fraudulent voice calls more convincing and easier to conduct.

CrowdStrike said vishing is also attractive to attackers because it can bypass managed endpoints and traditional security controls while leaving limited forensic evidence.

The report warned that AI is reducing the time organizations have to address newly discovered vulnerabilities. While cybersecurity teams previously operated around a 30-day patching window, CrowdStrike said 88% of vulnerabilities are now weaponized within 48 hours.

Meyers cited the React2Shell vulnerability, which was exploited against a CrowdStrike customer less than six hours after its disclosure. Two more exploitation attempts were detected within the next two days.

Based on the speed and proximity of the attacks, Meyers said attackers may have used AI to develop an exploit resource and share it with other adversaries.

The report also identified enterprise AI systems and their supporting software supply chains as growing attack surfaces.

About 48,000 Common Vulnerabilities and Exposures, or CVEs, were published in 2025. Another 43,000 were published from January through June 2026, representing a 62% year-on-year increase, according to the report.

CrowdStrike said attackers are infiltrating developer ecosystems, including continuous integration and delivery or deployment pipelines, integrated development environment extensions, and software repositories. Compromising these systems can allow attackers to insert malicious code into software distributed to downstream organizations.

During the first half of 2026, malicious packages accounted for 87% of the software registry threats identified by CrowdStrike. Organizations commonly download packages to add features and functions to their applications.

The company also warned about security gaps between legacy systems, cloud infrastructure, endpoints, and software-as-a-service applications. Poor integration and monitoring across these environments can limit visibility and provide attackers with possible entry points.

AI credentials have likewise become targets. CrowdStrike highlighted “LLM jacking,” in which attackers steal legitimate credentials to access large language models or computing resources.

The stolen access can be used for activities such as cryptomining, unauthorized model use, and cost harvesting, leaving the victim responsible for the resulting expenses.

Meyers urged organizations to secure AI systems and software supply chains, close visibility gaps across technology environments, protect identities and SaaS applications, and improve their understanding of threat actors.

“Securing AI is a new area that most organizations haven’t embraced fully yet and something that they need to,” Meyers said. “The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary.”

The report covered data collected from July 2025 through June 2026 by CrowdStrike’s OverWatch managed threat-hunting team, which the company said analyzes more than seven trillion signals daily.

- Advertisement -spot_img

RELEVANT STORIES

spot_img

LATEST

- Advertisement -spot_img