Cybercriminals are increasingly using artificial intelligence both to launch attacks and to target enterprise AI systems, according to CrowdStrike’s 2026 Threat Hunting Report. The company said its Falcon platform detected 2.5 times more AI agent-driven activity on endpoints than human-driven activity during the first quarter of 2026. Attackers are using AI to automate tasks such as generating scripts, payloads and exploitation commands, dramatically reducing attack preparation time. CrowdStrike also found that 88 percent of newly disclosed vulnerabilities are weaponized within 48 hours, replacing the traditional 30-day patch window. The report warns that enterprise AI platforms, software supply chains and model infrastructure have become attractive attack targets. It also highlights the rise of LLM jacking, where stolen credentials are used to access language models or generate fraudulent computing costs, alongside a sharp increase in AI-assisted voice phishing attacks.
Cybercriminals are increasingly using artificial intelligence both to launch attacks and to target enterprise AI systems, according to CrowdStrike’s 2026 Threat Hunting Report. The company said its Falcon platform detected 2.5 times more AI agent-driven activity on endpoints than human-driven activity during the first quarter of 2026. Attackers are using AI to automate tasks such as generating scripts, payloads and exploitation commands, dramatically reducing attack preparation time. CrowdStrike also found that 88 percent of newly disclosed vulnerabilities are weaponized within 48 hours, replacing the traditional 30-day patch window. The report warns that enterprise AI platforms, software supply chains and model infrastructure have become attractive attack targets. It also highlights the rise of LLM jacking, where stolen credentials are used to access language models or generate fraudulent computing costs, alongside a sharp increase in AI-assisted voice phishing attacks.