Urgent.News

What's breaking now, across thousands of outlets.

AI

CrowdStrike finds AI systems under direct attack as exploit windows shrink

Artificial intelligence has become a target for attackers rather than only a tool they use, according to CrowdStrike Holdings Inc.’s “2026 Threat Hunting Report,” released today. The annual report draws on observations from CrowdStrike’s OverWatch threat hunting team and intelligence analysts tracking more than 290 named adversaries over the 12 months to June 30. Previous […] The post CrowdStrike…

CrowdStrike finds AI systems under direct attack as exploit windows shrink

CrowdStrike's annual "2026 Threat Hunting Report" reveals that artificial intelligence systems are increasingly becoming direct targets for attackers, rather than just tools used by adversaries. The report, based on observations from CrowdStrike's OverWatch threat hunting team, shows that the exploitation window for AI-related exploits has shrunk to hours rather than days.

North Korean group Chollima and Chinese groups React2Shell and Vault Panda have both exploited vulnerabilities within 24 hours of their public disclosure. AI infrastructure itself is now being probed directly, with AI model access accounting for 16% of the MITRE ATLAS techniques observed by CrowdStrike. Adversaries are hijacking large language models through a practice called "LLMjacking," where they escalate compromised identities to administrator privileges and submit use-case forms to unlock model access.

Corporate AI tools, such as foundation model services, are being targeted for API overloads. Software registries, particularly npm packages, remain the shortest path into developer environments, with malicious packages accounting for 87% of identified threats. Cloud-focused groups like Altered Spider can compromise over 300 software dependencies in a single day using stolen maintainer credentials.

Identity abuse, such as vishing intrusions, has doubled in the first half of 2026 compared to the second half of 2025. Monthly device code phishing attempts have risen 15-fold over the past six months. Overall, intrusion activity rose roughly 4% this year, down from a 27% surge the previous year, but still significant when including automated attacks.

The report emphasizes the need for organizations to secure AI systems as aggressively as they adopt them, using AI to defend at the speed of the adversary.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in AI

More from Monday 3 August →