AI is both a cyber weapon and a massive target, CrowdStrike warns
Follow ZDNET: Add us as a preferred source on Google.

Follow ZDNET: Add us as a preferred source on Google.
Artificial intelligence is increasingly "an adversary tool and target," researchers said, forcing businesses to rethink their defensive strategies in light of attack signals far outstripping what cybersecurity experts can manually handle.
According to CrowdStrike's 2026 Threat Hunting Report, published on Monday, the same AI models, tools, and workflows that are giving businesses growth and productivity opportunities are being weaponized by cybercriminals in droves.
Also: How Google used AI agents to find and fix 1,072 Chrome security bugs - in 60 days
As corporate networks expand, endpoint devices are added, and new large language models (LLMs) are deployed to handle various workloads, organizations are also unwittingly creating larger "undefended" attack surfaces that can be exploited to steal data, obtain AI model access, conduct surveillance, and potentially even harvest computing power for their own ends.
"AI is not just the tool or weapon that is being used, but it is also the attack surface," Adam Meyers, head of threat intel at CrowdStrike, commented. "We're seeing threat actors really adopt AI at the same speed that everybody else is."
CrowdStrike's report said that the widespread adoption of artificial intelligence (much of it new and unproven) is increasing the sheer volume of signals that defenders have to sort through.
Also: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
There are now 2.5 times as many AI agent-triggered leads for the firm's threat hunters to examine as there are manually driven leads, which CrowdStrike said "makes it more difficult for defenders to distinguish malicious activity from expected AI-driven behavior."
Suspicious alerts and signals underscore AI-driven activity in the criminal world -- and the rapid speeds at which attacks are now being conducted. CrowdStrike gave a number of examples, including:
AI is mostly used by cybercriminals today to generate phishing and vishing material, payloads, and commands, streamlining their attack chains and potentially creating more convincing phishing schemes designed for initial access. Meyers said these creations are becoming more bespoke, with custom tools generated by AI and LLMs to manage different defense scenarios.
Another concerning trend highlighted in the report is the shrinking window that human defenders -- and their tools -- have to respond between vulnerability discovery and exploitation.
Source: ZDNet