Key takeaways

  • Artificial intelligence is increasingly "an adversary tool and target," researchers said, forcing businesses to rethink their defensive…
  • As corporate networks expand, endpoint devices are added, and new large language models (LLMs) are deployed to handle various workloads…
  • "AI is not just the tool or weapon that is being used, but it is also the attack surface," Adam Meyers, head of threat intel at…

What happened

Artificial intelligence is increasingly "an adversary tool and target," researchers said, forcing businesses to rethink their defensive strategies in light of attack signals far outstripping what cybersecurity experts can manually handle. According to CrowdStrike's 2026 Threat Hunting Report, published on Monday, the same AI models, tools, and workflows that are giving businesses growth and productivity opportunities are being weaponized by cybercriminals in droves.

From January through June 2026, 88% of exploits detected by CrowdStrike were launched within 48 hours of a public proof-of-concept (PoC) code release. Some threat groups, such as China's Vault Panda and Genesis Panda, are keeping an even closer eye on new bugs: They developed working exploits for a critical vulnerability in a web application (React2Shell) within a day of disclosure. In these situations, AI goes both ways.

Why it matters

As corporate networks expand, endpoint devices are added, and new large language models (LLMs) are deployed to handle various workloads, organizations are also unwittingly creating larger "undefended" attack surfaces that can be exploited to steal data, obtain AI model access, conduct surveillance, and potentially even harvest computing power for their own ends.

"AI is not just the tool or weapon that is being used, but it is also the attack surface," Adam Meyers, head of threat intel at CrowdStrike, commented. " CrowdStrike's report said that the widespread adoption of artificial intelligence (much of it new and unproven) is increasing the sheer volume of signals that defenders have to sort through.

" Suspicious alerts and signals underscore AI-driven activity in the criminal world -- and the rapid speeds at which attacks are now being conducted. CrowdStrike gave a number of examples, including: AI is mostly used by cybercriminals today to generate phishing and vishing material, payloads, and commands, streamlining their attack chains and potentially creating more convincing phishing schemes designed for initial access.

Meyers said these creations are becoming more bespoke, with custom tools generated by AI and LLMs to manage different defense scenarios. Another concerning trend highlighted in the report is the shrinking window that human defenders -- and their tools -- have to respond between vulnerability discovery and exploitation.

What to watch

" What does this mean for the enterprise and its cybersecurity teams? According to CrowdStrike, response times are going to become shorter and shorter -- no doubt due in part to the weaponization of AI. "While this pattern predates the emergence of frontier AI models, the implementation of these systems is likely to compress vulnerability exploitation timelines by accelerating vulnerability discovery and exploit development," the researchers said.

" AI can act as a shield, but as CrowdStrike's research revealed, it can also be a weapon. With the pressure caused by AI, defenders will be hard-pressed to retain control and secure the networks and endpoints they are responsible for, and so the team recommended that businesses adopt the following practices: