Urgent.News

600+ sources. One page. See who else covered it.

Editions

AI

AI is 'both the weapon and the target' in latest wave of cyberattacks

CrowdStrike tracks 89% surge in machine-assisted activity as patch windows shrink to 48 hours

AI is 'both the weapon and the target' in latest wave of cyberattacks

AI is rapidly evolving into both a potent weapon and a lucrative target in the burgeoning landscape of cyberattacks, according to the latest findings from CrowdStrike. In 2025, attacks by AI-enabled adversaries have surged by an astounding 89 percent, as detailed in the security firm's annual Threat Hunting Report. Criminal gangs and nation-state actors are increasingly leveraging AI throughout the entire attack process, from initial access to post-exploitation activities.

CrowdStrike's senior vice president for adversary operations, Adam Meyers, emphasized that "AI is both the weapon and the target," highlighting the growing value of AI as an attack surface and the increasing utilization of AI by threat actors.

Attackers are employing AI to compromise organizations' AI infrastructure and popular software packages, manipulating them for malicious purposes. This includes a technique known as LLMjacking, where criminals steal corporate credentials to access advanced AI models. There's also the insidious practice of cost harvesting, where attackers deliberately inflate AI usage to rack up excessive bills.

One particularly egregious example documented by CrowdStrike involved a token thief sending a staggering 200,000 API requests within just two minutes.

CrowdStrike's threat hunting team now tracks AI-triggered leads at twice the rate of human-driven threats, a trend that holds true for both state-sponsored threat groups and financially motivated criminals. The firm has identified over 290 adversary groups, adding roughly ten new groups this year alone. Among these, North Korea's sub-unit, Famous Chollima, stands out for its advanced AI capabilities.

This group has demonstrated remarkable proficiency in creating fake companies with AI-generated websites, GitHub accounts, and email infrastructure to support insider threat operations.

Supply-chain compromise is the second most common MITRE ATLAS technique employed by attackers to gain initial access. Famous Chollima's campaign targeting AI-focused development environments serves as a prime example of this technique, involving the publication of trojanized repositories on GitHub that contained malicious scripts alongside benign-looking project files. When developers opened these repositories, the malicious scripts executed commands that granted Famous Chollima access to the developers' environments.

Moreover, AI itself is becoming a target through its dependence on Continuous Integration/Continuous Deployment (CI/CD) pipelines. This poses a significant threat as AIs can be exploited through vulnerabilities in these pipelines. CrowdStrike suspects another Lazarus Group offshoot, known as Stardust Chollima or Sapphire Sleet, behind the March Axios supply chain attack.

Amazon recently attributed four npm compromises, affecting software dependencies, to the same North Korean crew. Meanwhile, a financially motivated group dubbed Altered Spider targeted developers' AI tools, compromising over 300 software dependencies in a single day.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in AI

Build a Privacy Filter Before Your AI Agent Remembers User Actions

AI agents are starting to remember more than chats. They can watch clicks, typed text, app switches, browser context, files, tool calls, and workflow history.

  • AI agents are increasingly remembering user actions like clicks and typed text.
  • Privacy filters process user activity before it becomes part of an agent's memory.

Building Roshni: A Real-Time, Multi-Agent Financial Voice AI for Bharat 🇮🇳

Building Roshni: An Ultra-Low Latency, Multi-Agent Financial Voice Assistant for Bharat 🇮🇳 How I built an end-to-end, multilingual financial voice AI using Murf Falcon, LiveKit Agents, Deepgram…

  • Roshni AI assists Indian citizens with financial queries in voice interactions.
  • Supports English, Hindi, and Hinglish languages with ultra-low latency.
  • Maintains user memories via SQLite for personalized financial advice.

A beginner's guide to the Qwen3.8-27b model by Qwen on Huggingface

This is a simplified guide to an AI model called Qwen3.8-27b maintained by Qwen . If you like these kinds of analysis, you should join AImodels.fyi or follow us on Twitter .

  • Qwen3.8-27B is a 27-billion-parameter AI model with built-in vision capabilities
  • Excels in software engineering, coding, and multimodal computer use tasks
  • Requires significant hardware resources for deployment