AI Now Powers Adversary Attacks, CrowdStrike Warns

email scam - sextortion

CrowdStrike has released its 2026 Threat Hunting Report, warning that artificial intelligence is now embedded across modern adversary operations — used simultaneously as a tool, a target, and a force multiplier by threat actors.

Drawing on frontline intelligence from CrowdStrike’s threat hunters and analysts tracking more than 290 named adversaries, the report found that China-nexus adversaries exploited critical vulnerabilities within 24 hours of a public proof-of-concept release, while DPRK-nexus actors poisoned 131 trusted AI framework packages — evidence, CrowdStrike says, that AI has become both an operational capability for attackers and a high-value target in its own right.

Exploitation windows collapse to hours

The report found that 88 per cent of CrowdStrike-observed exploitation of vulnerabilities with a proof-of-concept occurred within 48 hours of release in the first half of 2026. China-nexus actors tracked as VAULT PANDA and GENESIS PANDA moved even faster, launching deliberate attacks within 24 hours of disclosure.

Threat actors are also using AI directly in their operations, generating payloads and shell commands, exploiting AI infrastructure, and abusing enterprise large language models. One campaign sent nearly 200,000 AI model requests within two minutes. CrowdStrike’s OverWatch team observed AI agent-triggered detection leads growing at 2.5 times the rate of human-triggered leads, a sign of how AI is accelerating the volume and speed of activity security teams must investigate.

The AI supply chain becomes a battleground

The report identifies the AI ecosystem as the next major supply chain battleground. The DPRK-nexus group tracked as STARDUST CHOLLIMA injected a malicious npm package into 131 trusted Mastra AI frameworks, while 87 per cent of software registry threats identified in the first half of 2026 involved malicious npm packages. Separately, the eCrime group ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.

Cloud-conscious eCrime activity surged 171 per cent as adversaries carried out credential theft, cryptomining, LLM abuse and digital financial asset theft. Trusted authentication channels also came under increasing attack: vishing intrusions doubled in the first half of 2026, with groups tracked as CORDIAL SPIDER and SNARKY SPIDER compromising single sign-on-integrated SaaS applications for data exfiltration. In one incident, SNARKY SPIDER moved from account takeover to data theft in under five minutes, while monthly device code phishing attempts rose 15-fold over the same period.

“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” said Adam Meyers, head of counter adversary operations at CrowdStrike. “The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary.”

The findings point to a shift in the operational reality facing enterprise security teams: attacks that move faster, scale more efficiently, and increasingly target the AI systems organisations are racing to deploy.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading