CrowdStrike: AI attacks surge 89% in 2025 as patch windows collapse to 48 hours
Machine speed is weaponizing new bugs while adversaries steal AI access and inflate AI bills.

CrowdStrike says AI-enabled attacks rose 89% in 2025 and that machine-assisted activity surged by 89%, as patch windows shrink to 48 hours. The result is a dual threat: AI systems are being targeted, and organizations must patch faster while guarding AI infrastructure.
CrowdStrike is seeing an 89% surge in AI-related, machine-assisted activity tied to cyberattacks in 2025, and the firm’s Threat Hunting Report argues the timeline for defense has broken. It says exploitation using public proof-of-concept code happened within 48 hours of disclosure 88% of the time from January to June, and China-linked groups such as Vault Panda and Genesis Panda moved even faster, launching attacks within 24 hours. In plain English: even if you patch, the race is now so short that attackers can often convert newly public flaws into working attacks before the typical organization finishes responding.
CrowdStrike frames the shift with a blunt line attributed to its own leadership: “AI is both the weapon and the target,” said CrowdStrike counter adversary division senior VP Adam Meyers. That matters because the focus is no longer just on keeping attackers out. It is also about stopping attackers from using AI through the attack chain, while defenders find themselves defending AI infrastructure itself, including the systems and software the AI depends on.
So what does “AI as a weapon” look like in the report? CrowdStrike says criminal gangs and nation states are using AI throughout the attack chain, including tactics that directly target access to frontier-model APIs. One example is LLMjacking, where criminals steal corporate credentials to access frontier-model APIs. Another example is cost harvesting, where adversaries deliberately inflate a victim’s AI usage to run up a bill. CrowdStrike also documents a token thief campaign that sent about 200,000 API requests in just two minutes, a detail that should land uncomfortably with anyone budgeting for AI usage. If your AI spend can be gamed at machine speed, finance becomes a security domain.
The “AI as a target” part is equally concrete. CrowdStrike describes attackers targeting organizations’ AI infrastructure and poisoning popular software packages to compromise users. That supply-chain angle is not theoretical. CrowdStrike notes that AI supply-chain compromise was the second most common MITRE ATLAS technique used by attackers to gain initial access. It also highlights a specific threat cluster it tracks as Famous Chollima, a sub-unit under the Lazarus Group umbrella and best known for fake IT worker scams. CrowdStrike says Famous Chollima demonstrated the most advanced AI usage over the second half of 2025 and first half of 2026. The report authors write that this government-backed crew created “entire fake companies with AI-generated websites, GitHub accounts, and email infrastructure” to support insider threat operations.
Famous Chollima also shows up in supply-chain compromises aimed at AI-focused development environments. CrowdStrike calls out a supply-chain attack in January and February targeting cryptocurrency and blockchain companies. In these attacks, the Norks published trojanized repositories, primarily hosted on GitHub, that contained legitimate-looking project files plus hidden, malicious scripts. When developers opened the repositories, the scripts automatically executed commands that gave Famous Chollima access to their environments. CrowdStrike connects this directly to the AI stack by noting that “AIs themselves are being targeted through that supply chain and through the CI/CD pipelines that they're dependent on.” For executives, the second-order implication is nasty: even if you lock down the AI app, a compromised build pipeline can rewrite what gets deployed and who gets access.
CrowdStrike also ties speed and ecosystem effects to the patch problem. Meyers argues that AI is helping attackers exploit newly disclosed vulnerabilities at machine speed, creating a “rich ecosystem of vulnerabilities” for attackers to use. He says the 30-day patch window, which he calls “aspirational,” is obsolete, and organizations are down to 24-hour and 48-hour patch cycles. That’s consistent with the report’s earlier observation about PoC-driven exploitation: from January to June, 88% of observed exploitation occurred within 48 hours of public PoC release. And the number of vulnerabilities being fired into that short runway is rising. Meyers says there were something like 48,200 CVEs registered in 2025, and “we’re already, as of last week, at 43,000 for this year,” with the year not even into August. He adds that June alone saw more than 7,600 software bugs reported and tracked through CVEs. CrowdStrike’s framing is that the vulnerability ecosystem is poised to be the big story for the next couple months.
The report also points to adversaries moving through software supply chains and cloud environments at breakneck speed. CrowdStrike says it tracks more than 290 adversary groups, adding about ten this year. It suspects another Lazarus Group offshoot tracked as Stardust Chollima or Sapphire Sleet was behind the March Axios supply chain attack. Last week, Amazon attributed four npm compromises over the past 18 months to the same North Korean crew. Meanwhile, a financially motivated crew tracked by CrowdStrike as Altered Spider and elsewhere as TeamPCP targeted developers’ AI tools, compromising more than 300 software dependencies in one day. CrowdStrike says the actors harvested credentials and secrets before pivoting into cloud environments for theft and extortion. Meyers says Altered Spider “hits the endpoint in seconds and within minutes, they're inside of the cloud,” tying that speed back to software supply chains.
For boards, CISOs, and execs responsible for resilient operations, the strategic stake is simple: defensive planning cannot treat AI as a standalone initiative. The report portrays AI security as inseparable from identity, developer tooling, dependency management, CI/CD integrity, and the governance of AI usage costs. When attacks arrive within 24 to 48 hours of vulnerability disclosure and also manipulate AI access and billing, the question becomes how fast your organization can detect, patch, and contain across the entire software and AI lifecycle, not just the model itself. If that sounds like operational math, it is. And if you ignore it, CrowdStrike’s data suggests you will get outpaced.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology
Cyborg cockroaches can now carry cameras and inject medicine on command
A WIRED report shows electrodes, cameras, and injection devices turning live roaches into remote medics for disaster rescue.
Isar Aerospace's Spectrum reaches orbit on second flight, a European commercial first
The German startup's second-flight success lands days before Macron's Paris summit, giving Europe a homegrown launch option as SpaceX and Blue Origin bow out.
Tesla's wheel-less Cybercab rolls into China as sales stall
The EV maker will debut its autonomous robotaxi in Beijing and Shanghai mid-September, hoping its tech wow-factor reignites demand in its second-largest market.




