A New Era of Cyberattacks: How AI Has Become Both a Weapon and a Target
The cybersecurity landscape has taken a drastic turn in recent times. Artificial intelligence (AI) was initially touted as a game-changer for defenders, helping to identify and mitigate threats more efficiently than human analysts alone. However, a new report from CrowdStrike reveals that the tables have turned: AI is now being used by attackers on an unprecedented scale, creating more noise than human-triggered incidents in the process.
According to CrowdStrike’s threat hunting team, AI agent-driven behaviors have surged past human triggers, resulting in an average of 14 million detection leads daily. This staggering figure translates to around 36,000 customer alerts per day for the company’s clients. The sheer volume of these alerts highlights just how extensively attackers are leveraging AI to carry out their operations.
The AI-powered threat landscape is characterized by increased targeting of software defects, open-source supply chains, and even AI tools themselves. This has created a perfect storm of challenges for defenders, who must contend with an extended attack surface and the constant evolution of threats. “AI tools that are being implemented by every enterprise across the globe right now are also creating an extended attack surface,” said Adam Meyers, senior vice president of counter adversary operations at CrowdStrike.
The report’s authors paint a grim picture of AI’s impact on vulnerabilities. A staggering 88% of vulnerabilities were weaponized through AI within just 48 hours, rendering traditional patch windows obsolete. Organisations are now struggling to keep pace with the accelerated threat landscape, forced to adopt new baseline patch cycles of 24-48 hours.
The use of frontier AI models by attackers is particularly concerning. These models enable the development of sophisticated resources such as AI-generated scripts, payloads, and commands that significantly enhance an attacker’s capabilities. The technology also allows for more creative approaches to automated attacks, amplifying their impact by manipulating or sabotaging AI systems and data.
Meyers emphasized that most organisations are not taking adequate steps to secure their AI tools or address the threat posed by attackers using AI against them. “AI is both the weapon and the target,” he noted. As a result, defenders must take immediate action to safeguard their AI infrastructure and ensure it does not become a liability in the fight against cyber threats.
Ultimately, this report serves as a stark reminder of the urgent need for organisations to prioritise AI security. By acknowledging the risks and taking proactive measures to mitigate them, we can prevent the AI ecosystem from becoming a fertile ground for attackers to exploit. As Meyers aptly put it: “We have to secure AI. This is absolutely critical.”
Source: CyberScoop — 2026-08-03