{
  "id": 74365,
  "title": "AI is 'both the weapon and the target' in latest wave of cyberattacks",
  "url": "https://urgent.news/2026/08/03/ai-is-both-the-weapon-and-the-target-in-latest-wave-of-cyberattacks",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-03T07:01:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/cyber-crime/2026/08/03/ai-is-both-the-weapon-and-the-target-in-latest-wave-of-cyberattacks/5281534"
  },
  "original_language": "en",
  "account": "AI is rapidly evolving into both a potent weapon and a lucrative target in the burgeoning landscape of cyberattacks, according to the latest findings from CrowdStrike. In 2025, attacks by AI-enabled adversaries have surged by an astounding 89 percent, as detailed in the security firm's annual Threat Hunting Report. Criminal gangs and nation-state actors are increasingly leveraging AI throughout the entire attack process, from initial access to post-exploitation activities. CrowdStrike's senior vice president for adversary operations, Adam Meyers, emphasized that \"AI is both the weapon and the target,\" highlighting the growing value of AI as an attack surface and the increasing utilization of AI by threat actors.\n\nAttackers are employing AI to compromise organizations' AI infrastructure and popular software packages, manipulating them for malicious purposes. This includes a technique known as LLMjacking, where criminals steal corporate credentials to access advanced AI models. There's also the insidious practice of cost harvesting, where attackers deliberately inflate AI usage to rack up excessive bills. One particularly egregious example documented by CrowdStrike involved a token thief sending a staggering 200,000 API requests within just two minutes.\n\nCrowdStrike's threat hunting team now tracks AI-triggered leads at twice the rate of human-driven threats, a trend that holds true for both state-sponsored threat groups and financially motivated criminals. The firm has identified over 290 adversary groups, adding roughly ten new groups this year alone. Among these, North Korea's sub-unit, Famous Chollima, stands out for its advanced AI capabilities. This group has demonstrated remarkable proficiency in creating fake companies with AI-generated websites, GitHub accounts, and email infrastructure to support insider threat operations.\n\nSupply-chain compromise is the second most common MITRE ATLAS technique employed by attackers to gain initial access. Famous Chollima's campaign targeting AI-focused development environments serves as a prime example of this technique, involving the publication of trojanized repositories on GitHub that contained malicious scripts alongside benign-looking project files. When developers opened these repositories, the malicious scripts executed commands that granted Famous Chollima access to the developers' environments.\n\nMoreover, AI itself is becoming a target through its dependence on Continuous Integration/Continuous Deployment (CI/CD) pipelines. This poses a significant threat as AIs can be exploited through vulnerabilities in these pipelines. CrowdStrike suspects another Lazarus Group offshoot, known as Stardust Chollima or Sapphire Sleet, behind the March Axios supply chain attack. Amazon recently attributed four npm compromises, affecting software dependencies, to the same North Korean crew. Meanwhile, a financially motivated group dubbed Altered Spider targeted developers' AI tools, compromising over 300 software dependencies in a single day.",
  "summary": "CrowdStrike tracks 89% surge in machine-assisted activity as patch windows shrink to 48 hours",
  "key_points": [
    "AI attacks surge 89% in 2025, per CrowdStrike's Threat Hunting Report",
    "AI used as weapon and target in cyberattacks, increasing attack surface",
    "North Korea's Famous Chollima group excels in AI capabilities for insider threats"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "AI is 'both the weapon and the target' in latest wave of cyberattacks",
        "url": "https://urgent.news/2026/08/03/ai-is-both-the-weapon-and-the-target-in-latest-wave-of-cyberattacks-75283",
        "published": "2026-08-03T07:01:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}