Threats

AI Cyberattacks Surge 89%

August 3, 2026 08:00 · 10 min read
AI Cyberattacks Surge 89%

AI: The Double-Edged Sword in Cybersecurity

Artificial intelligence (AI) has become a crucial component in the realm of cybersecurity, but it also poses significant threats. According to CrowdStrike's annual threat hunting report, AI is now both the weapon and the target in cyberattacks. The company's threat hunting team and systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts during the one-year period ending in June.

The Rise of AI-Driven Behaviors

Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, stated that AI agent-driven behaviors have surged past human triggers. This surge in AI-driven behaviors has led to a significant increase in detections, with AI driving the detections significantly above what humans are causing. Meyers noted that this gives a sense of how frequently AI is being used and that it's being used everywhere.

The threat posed by AI showed up incessantly during the past year, sparking alarming shifts and heightened targeting across software defects, open-source supply chains, and AI tools themselves. This creates greater difficulties for defenders, as the AI tools being implemented by every enterprise across the globe are also creating an extended attack surface.

AI: A Tool, Target, and Force Multiplier

Researchers wrote in the report that AI is now a tool, a target, and a force multiplier for adversaries. AI-enabled malicious activity surged 89% during the past year as attackers used the technology to scale operations, hasten tradecraft, and target AI infrastructure. Attackers are using frontier AI models to uncover vulnerabilities and develop resources, including AI-generated scripts, payloads, and commands that increase their effectiveness and efficiency.

The technology also allows threat groups to design more creative ways to run automated attacks and boost impact by manipulating, interrupting, or sabotaging AI systems and data. Meyers stated that AI is both the weapon and the target, but most organizations don't view it as such and haven't secured or put proper guardrails around the AI tools they use or address the ways attackers can use AI against them.

Vulnerabilities and Patch Cycles

Meyers described one of the scarier stats in this year's report: 88% of vulnerabilities were weaponized through AI within 48 hours. This creates a rich ecosystem of vulnerabilities for attackers to use against various systems and renders the 30-day patch window obsolete, forcing organizations to struggle under a new baseline patch cycle of 24 to 48 hours.

The AI ecosystem also became the next software supply chain battleground during the past year, as evidenced by TeamPCP's rampage through open-source software in the first half of this year. The threat cluster compromised more than 300 software dependencies in one day, Meyers said.

Securing AI

AI tools are already in the crosshairs, and the attack surface will continue to grow as agentic systems, AI application integrations, and dependency managers for AI agents proliferate. The report concluded that the same AI tools driving modern businesses are creating under-defended attack surfaces that adversaries are exploiting. Meyers emphasized that securing AI is absolutely critical, stating, "We have to secure AI. This is absolutely critical."


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free