ANALYSIS

AI Has Become Both the Weapon and the Target, CrowdStrike's Latest Report Finds

A red AI chip caught in a crosshair over a field of code packages, on a black field, representing AI as both weapon and target in cyberattacks
CrowdStrike finds AI is now embedded across adversary operations, and a target in its own right. Source: CrowdStrike
TLDR

The attack surface is now the AI toolchain

For most of the past two years, the security conversation around AI focused on what models might say or leak. CrowdStrike's report, which covers active investigations from July 2025 through June 2026, reframes the risk. The most consequential finding is not that chatbots misbehave. It is that the infrastructure companies are racing to build agents on has become a place to attack them.

The clearest example is the Mastra framework, an open-source toolkit for building AI agents. DPRK-nexus actor STARDUST CHOLLIMA injected a malicious npm package into 131 trusted components of it, so that a developer pulling in a routine dependency could unknowingly pull in the attacker's code. This is supply-chain compromise aimed squarely at the AI build process. The victim is not the model. It is the team assembling an agent, and every system that agent will later touch.

"AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend."
Adam Meyers, head of Counter Adversary Operations at CrowdStrike, via the 2026 Threat Hunting Report

Offense is automating faster than defense

The report's numbers describe a speed problem. AI-enabled adversary operations climbed 89 percent from the prior year, and detection leads triggered by AI agents grew at 2.5 times the rate of human-triggered ones. Attackers are not just using AI to write better phishing lures. They are using it to compress the time between a vulnerability becoming public and that vulnerability being exploited.

Bar chart comparing the growth rate of human-triggered attack detection leads at 1.0 against AI agent-triggered leads at 2.5 times that rate
Detection leads triggered by AI agents are growing 2.5 times faster than human-triggered ones. Source: CrowdStrike 2026 Threat Hunting Report.

That compression shows up in the exploitation data. From January through June 2026, 88 percent of observed exploitation of vulnerabilities that had a public proof of concept happened within 48 hours of that code becoming available, and China-nexus adversaries moved inside 24 hours. When a patch race is measured in hours, the manual, human-paced side of defense is structurally behind. The team that has to read, triage, and remediate is racing software that does not sleep.

CrowdStrike 2026 Threat Hunting Report
Year over year rise in AI-enabled adversary operations89%
Mastra AI framework components hit by a malicious package131
Software dependencies one eCrime actor poisoned in a single day300+
Source: CrowdStrike 2026 Threat Hunting Report.

Why this lands on the AI buildout specifically

The supply-chain angle is what makes the report matter beyond security teams. The whole premise of the current AI wave is speed: pull an open-source framework, wire in a few packages, ship an agent. That velocity depends on trust in the npm and package registries every developer draws from, and CrowdStrike found that 87 percent of identified software-registry threats in the first half of 2026 involved malicious npm packages. The same registries that make agent development fast are the ones adversaries have learned to seed.

The velocity that makes AI development fast is the same velocity attackers now exploit. Every borrowed package is a door, and the industry has been building agents by opening as many doors as it can.

It also connects a run of incidents Santage has tracked this year. An OpenAI model autonomously chained credentials to breach Hugging Face in a red-team test. Anthropic disclosed that its models were used to breach corporate networks during safety testing. Cyera paid a billion dollars for Oasis to police machine identities. CrowdStrike's report is the macro layer under those single events: agents are proliferating, each one carries credentials and the ability to act, and the tools used to build and run them are now contested ground. The threat is not hypothetical, and it is not one company's problem.

What defenders actually have to do

The uncomfortable implication is that adopting AI and securing AI can no longer be sequential. A company that stands up dozens of agents this quarter and plans to govern them next quarter is running exactly the gap attackers are automating against. The report's own framing is that defense has to move at the same speed as the offense, which in practice means using AI to triage and respond rather than treating it as a future upgrade.

The organizations that succeed will secure AI as aggressively as they adopt it, and use AI to defend at the speed of the adversary.

That line, from CrowdStrike's Adam Meyers, is the report's thesis in a sentence, and it cuts against the way most enterprises have sequenced the work. The demand signal it creates is real: identity governance for agents, provenance checks on dependencies, and monitoring that runs at machine speed all become budget items rather than aspirations. The caution is that fear can overshoot, and vendors selling AI defense have an obvious incentive to describe the threat in its darkest terms. But the underlying data here comes from front-line investigations, not a marketing survey, and it points one direction. The attack surface expanded to include the AI itself, and the clock the defenders are racing got faster. The companies that keep treating security as the step after deployment are the ones this report is describing.

Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.