CrowdStrike finds AI systems under direct attack as exploit windows shrink
SiliconANGLE News · View original source

The latest findings from CrowdStrike Holdings Inc. highlight a significant shift in the landscape of cybersecurity, revealing that artificial intelligence (AI) systems are increasingly becoming direct targets for cyber attackers. This information comes from CrowdStrike's "2026 Threat Hunting Report," which was released today and draws on data collected by the company's OverWatch threat hunting team and intelligence analysts. The report covers observations of more than 290 named adversaries over the past year, up to June 30, and marks a methodological evolution in how cyber threats are assessed, now including automated attacks alongside traditional hands-on intrusions.
The report indicates a dramatic reduction in the exploitation window, which is now measured in hours rather than days. CrowdStrike analyzed the time gap between the public disclosure of a proof-of-concept exploit and the subsequent adoption of that exploit by attackers. Alarmingly, in 88% of cases between January and June, this gap was under 48 hours. This marks a significant increase from the previous year, where zero-day exploitations had already surged by 42%.
Two specific groups with ties to China, React2Shell and Vault Panda, exemplified this rapid response. They acted swiftly on a vulnerability disclosed on December 3, 2025, related to an unauthenticated remote code execution flaw in React Server Components and Next.js. Exploit code was available the very next day, with Vault Panda and Genesis Panda launching attacks within 24 hours. CrowdStrike's OverWatch team pursued over 800 leads related to these attacks, targeting more than 80 victims within the first four days of the vulnerability's disclosure.
The New Target: AI Infrastructure
The report illustrates a concerning trend: AI infrastructure itself is being directly targeted. Techniques for accessing AI models constituted 16% of the MITRE ATLAS techniques observed by CrowdStrike over the reporting year. One notable incident involved the capture of a malicious payload designed to exploit a Model Context Protocol server configuration, which could read the environment variables of a parent process and send sensitive configuration data to an external webhook.
Additionally, the report introduces the concept of "LLMjacking," where attackers hijack access to corporate large language models. In a May campaign against a cloud provider's foundational model service, a threat actor escalated a compromised identity to gain administrator privileges. This allowed them to submit a use-case form, which is necessary to unlock model access, and subsequently flood the system with nearly 200,000 application programming interface requests in just two minutes before throttling measures took effect.
Interestingly, adversaries are not only attacking AI but are also leveraging it for their operations. The North Korean group known as Famous Chollima has created entire fake companies using AI-generated websites, GitHub accounts, and email infrastructures to facilitate insider operations. The report notes that AI agent-triggered detection leads are now arriving at a rate 2.5 times faster than those triggered by human analysts, indicating a shift in the dynamics of threat detection.
The Broader Context of Cyber Threats
The report also highlights the continuing threat posed by malicious software registries, which remain a primary entry point into developer environments. In the first half of 2026, malicious npm packages accounted for 87% of identified threats from software registries. A notable incident involved the group Stardust Chollima compromising the Axios npm package by using stolen maintainer credentials. In another case, they injected a malicious npm dependency into at least 131 Mastra AI framework packages, exploiting a Mastra employee through social engineering tactics on LinkedIn.
The internet crime group known as Altered Spider operates on a different scale, utilizing self-propagating malware that takes stolen credentials to republish infected packages autonomously. In one instance, they compromised over 300 software dependencies in a single day during their May campaigns. This included poisoning Git tags on a publicly available GitHub Action, which could have led to credential-stealing malware being executed within automated build pipelines.
Identity abuse has also seen a marked increase, with vishing attacks—voice phishing—doubling in frequency in the first half of 2026 compared to the latter half of 2025. This follows a staggering 134% increase in such attacks between 2024 and 2025. Groups like Cordial Spider and Snarky Spider have employed vishing calls to direct targets to spoofed single sign-on pages, leading to swift account takeovers and data theft.
Overall, while intrusion activity rose by approximately 4%, this is a significant slowdown compared to the 27% increase reported the previous year. CrowdStrike attributes this plateau to adversaries concentrating their efforts on fewer but more complex campaigns. Technology remains the most targeted sector for the ninth consecutive year, with financial services and academic institutions experiencing the largest increases in attacks, at 11% and 17%, respectively.
In conclusion, Adam Meyers, head of counter adversary operations at CrowdStrike, encapsulated the findings by stating, "AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend." He emphasized the necessity for organizations to secure AI as aggressively as they adopt it and to leverage AI in their defense strategies to match the speed of adversaries.
Frequently asked questions
- What is LLMjacking?
- LLMjacking refers to the hijacking of access to corporate large language models by attackers, allowing them to exploit these systems for malicious purposes.
- How has the exploitation window changed?
- The exploitation window is now measured in hours rather than days, with 88% of cases showing a gap of under 48 hours between the public disclosure of a vulnerability and its exploitation by attackers.
- What role does AI play in current cyber threats?
- AI is being used by adversaries not only as a target but also as a tool to enhance their operations, leading to faster and more sophisticated attacks.
Related stories
AI & art news in your inbox, daily
The day's top stories, summarized. Free, no spam, unsubscribe anytime.
