"AI agent-driven behaviors have surged past human triggers," Adam Meyers said. The line, lifted from CrowdStrike's annual threat hunting report and repeated at a press briefing, captures a single, unsettling shift the company tracked over a one-year period ending in June: artificial intelligence is no longer only a defender's tool — it is the engine of attackers' activity and a target in its own right.
AI as weapon, target and force multiplier
“AI is now a tool, a target, and a force multiplier for adversaries,” researchers wrote in the CrowdStrike report, and the data provided to back that claim is stark. CrowdStrike's threat hunting team concluded that AI-enabled malicious activity surged 89% during the past year, as attackers harnessed frontier models to discover vulnerabilities, generate scripts, payloads and commands, and design more automated, creative attacks. The same automation that accelerates benign tasks is being repurposed to scale offensive tradecraft and to aim at AI systems and data themselves.
Detection scale: 14 million leads a day, 36,000 customer alerts
CrowdStrike’s systems and human threat hunters triaged an average of 14 million detection leads daily during the one-year period ending in June, yielding about 36,000 customer alerts. Those figures suggest that AI-driven signals now dominate the telemetry analysts must sift through: “AI has driven the detections significantly above what humans are causing,” Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, said during the press briefing.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Vulnerabilities weaponized in 48 hours — and the new patch baseline
The report highlights what Meyers called “one of the scarier stats”: 88% of vulnerabilities were weaponized through AI within 48 hours. That rapid weaponization, the report warns, is eroding the relevance of longer patch cycles: CrowdStrike’s analysis suggests the 30-day patch window has been made obsolete, creating a new baseline patch cycle of 24 to 48 hours for many organizations. The accelerated timeline flows from attackers using AI to quickly find exploit paths and generate working exploit code, compressing tasks that previously required more time and specialist expertise.
TeamPCP and the open-source supply chain battleground
The AI ecosystem also became a software supply chain battleground, the report says. In the first half of this year, the threat cluster TeamPCP “rampaged through open-source software,” compromising more than 300 software dependencies in one day, Meyers said. CrowdStrike researchers pointed to agentic systems, AI application integrations and dependency managers for AI agents as growing attack surfaces — areas where adversaries can insert malicious code, tamper with models or disrupt workflows that increasingly depend on third-party components.
What this means for technologists, policymakers, and procurement leaders
- Technologists and security teams: The report’s data forces a practical shift: defenders must assume faster exploit timelines and heavier volumes of AI-driven noise. Meyers framed the challenge bluntly — most organizations have not secured or added proper guardrails around AI tools — meaning defenders will need to harden AI integrations, monitor agentic behaviors, and adapt incident response to a 24–48 hour threat tempo.
- Policymakers and regulators: CrowdStrike’s findings underscore new governance questions around AI dependencies and the software supply chain. The rapid weaponization of vulnerabilities and the compromise of hundreds of open-source dependencies in a single day point to systemic risks that intersect with procurement standards, disclosure timelines and supply-chain risk management.
- Affected enterprises and procurement leaders: The report signals that deploying AI without parallel controls expands the enterprise attack surface. Meyers warned that “the AI tools that are being implemented by every enterprise across the globe right now are also creating an extended attack surface,” implying that purchasing decisions and vendor assessments should now include AI-specific security posture and dependency hygiene.
The CrowdStrike report leaves little doubt about the direction of travel: AI is embedded into both the offense and the defense, and the balance currently favors those who wield automation to accelerate discovery, exploitation and disruption. “AI is both the weapon and the target,” Meyers said. His closing imperative at the briefing is unambiguous: “We have to secure AI. This is absolutely critical.”
Source: https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/




