CrowdStrike: AI is now both the weapon and the target in cyberattacks

As AI-powered systems become increasingly ubiquitous in the digital landscape, they’re also becoming a double-edged sword in the world of cybersecurity. According to CrowdStrike’s latest threat hunting report, AI-driven behaviors have surpassed human-triggered incidents as the primary source of potential malicious activity detected by the company’s systems. This alarming trend highlights the need for organizations to rethink their approach to AI security and recognize that these intelligent systems are both a powerful tool and a vulnerable target.

The sheer volume of AI-related threats is staggering, with CrowdStrike’s threat hunting team and systems triaging an average of 14 million detection leads daily, resulting in approximately 36,000 customer alerts over the past year. This surge in AI-driven detections has outpaced human-triggered incidents by more than two to one, giving a glimpse into just how widespread the use of AI is becoming – and how attractive it has become as a target for malicious actors.

But what exactly does this mean? In simple terms, AI tools are being used not only to automate tasks and streamline processes but also to uncover vulnerabilities, develop malware, and even manipulate or sabotage other AI systems. This creates a cycle of escalating threat levels, where attackers use AI to scale their operations, hasten their tradecraft, and target the very infrastructure that underpins these intelligent systems.

One of the most concerning aspects of this trend is the way AI is being used to uncover vulnerabilities and exploit them. According to CrowdStrike’s report, a staggering 88% of vulnerabilities were weaponized through AI within just 48 hours – rendering traditional patch windows obsolete and forcing organizations to scramble to keep up with an ever-accelerating attack cycle.

This has significant implications for the way we approach software security. With the threat cluster known as TeamPCP recently unleashing chaos on open-source software, it’s clear that AI is not only a tool but also a target – and one that’s rapidly becoming a prime focus for attackers seeking to exploit its weaknesses. As the use of AI continues to proliferate across industries, organizations must recognize that their AI tools are creating new attack surfaces that need to be secured.

Ultimately, this calls for a fundamental shift in how we approach AI security. Rather than viewing these intelligent systems as simply another tool in our arsenal, we need to acknowledge their vulnerabilities and take steps to protect them – just as we would any other high-value asset. By doing so, we can prevent the very real danger of AI becoming a force multiplier for adversaries, rather than a powerful ally in our quest for cybersecurity.

So what can you do to stay ahead of this evolving threat landscape? First and foremost, recognize that your AI tools are not just an added layer of security but also a potential vulnerability. Start by implementing robust security measures specifically designed with AI systems in mind – such as monitoring their behavior, segregating them from critical infrastructure, and regularly updating their software. By taking these steps, you can help mitigate the risks associated with AI-driven threats and stay one step ahead of the attackers who are increasingly using these intelligent systems to wreak havoc on our digital world.


Source: CyberScoop — 2026-08-03