READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

CrowdStrike Report: Attackers Now Exploit New Vulnerabilities Within 48 Hours, AI Fuels Both Sides

CrowdStrike Report: Attackers Now Exploit New Vulnerabilities Within 48 Hours, AI Fuels Both Sides
CrowdStrike's 2026 Threat Hunting Report finds hackers are weaponizing the same AI tools businesses use for productivity, generating phishing content, custom malware, and attack code faster than human defenders can keep up. Companies that rushed to deploy AI without securing it are now sitting on attack surfaces nobody is watching.

Cybercriminals are using AI the same way corporate America is: to move faster and cut costs. The difference is what they're building with it.

CrowdStrike's 2026 Threat Hunting Report, published Monday, says AI has become both the weapon hackers use and the target they're aiming at. Businesses raced to deploy large language models across their networks for productivity gains. Now those same deployments are creating attack surfaces nobody fully secured, according to the report.

A 48-hour window, and shrinking

The most concrete number in the report: from January through June 2026, 88% of exploits CrowdStrike detected were launched within 48 hours of a public proof-of-concept code release.

That's the gap between a vulnerability going public and criminals having a working attack ready. Two days. For security teams, that means patching schedules built around weekly or monthly cycles are now obsolete for anything critical.

Adam Meyers, CrowdStrike's head of threat intel, put it plainly: "We're seeing threat actors really adopt AI at the same speed that everybody else is." Not slower. Not more cautiously. The same speed.

More noise, less signal

CrowdStrike's threat hunters are now getting 2.5 times as many AI agent-triggered leads to investigate compared to leads generated through manual detection methods. That sounds like a win for automation, until you consider the problem it creates.

The report says this volume "makes it more difficult for defenders to distinguish malicious activity from expected AI-driven behavior." In plain terms: when both attackers and normal business software are constantly triggering AI agents to do things, security teams can't tell the difference between a hacker's bot and a company's own automated workflow without extra digging. That digging takes time hackers aren't giving them.

What criminals are actually building

Right now, the report says, AI is mostly used by criminals for phishing and vishing (voice phishing) content, along with payloads and commands that streamline attack chains. Meyers said these tools are getting more custom-built, with AI generating bespoke code tailored to get around specific defenses a target has in place.

That's a meaningful shift from generic spam-style phishing to something closer to targeted, individualized social engineering, produced at a fraction of the labor cost it used to take a human operator.

The report also names specific state-linked groups adapting to this environment, including China-linked operations CrowdStrike tracks as Vault Panda and Genesis Panda, though the source material on their specific tactics was incomplete.

The other side of this: it's not just offense

AI is also catching bugs faster than humans could. Google has used AI agents to find and fix over a thousand Chrome security bugs in 60 days, a pace no human review team could match. Anthropic has publicly acknowledged instances where its Claude model was used in hacking activity and said that behavior "falls short of ideal behavior," which at least signals AI companies are watching for misuse rather than ignoring it.

So the honest picture is a genuine arms race, not a one-sided collapse. CrowdStrike has reported that 43% of companies say they've already experienced an AI-driven cybersecurity attack, which suggests this isn't theoretical for a huge chunk of the corporate world.

What this means for the vulnerability disclosure system

There's an unresolved tension baked into how vulnerability disclosure works. Security researchers publish proof-of-concept code so defenders can test and patch systems. That same code is exactly what criminals now weaponize within 48 hours, according to CrowdStrike's numbers.

Critics of the current disclosure model, including researchers who've long argued for staggered or delayed public release, will point to CrowdStrike's finding as validation. Defenders of full, fast disclosure counter that hiding vulnerability details just means defenders find out about them later too, from the same criminals exploiting them in silence. CrowdStrike's report doesn't settle that argument. It just confirms the clock has gotten shorter for everyone.

What happens next

CrowdStrike didn't announce new regulatory recommendations or call for government action in this report. It's a threat intelligence document aimed at corporate security teams, not policymakers.

The open question is whether companies that adopted AI tools for internal productivity, chatbots, coding assistants, automated customer service, are now going back and auditing what access those tools have to sensitive data. CrowdStrike's report suggests most haven't, given how it describes AI deployments as creating "undefended" attack surfaces. No specific companies were named as having been breached through this exact vector in the material CrowdStrike released Monday.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ZDNETAI is both a cyber weapon and a massive target, CrowdStrike warns