top of page

CrowdStrike Warns AI Is Both a Cyber Weapon and a Target

CrowdStrike has documented a sharp conflict behind the latest Google News cybersecurity coverage: organizations are deploying AI while attackers weaponize and target it. The security company says criminals and state-linked groups use generative AI to improve deception, accelerate operations, and support fraudulent identities. Those same groups are also attacking AI development tools, autonomous agents, credentials, and the data these systems can reach.

That combination changes the security calculation. An AI assistant is not merely another application that employees use. An agent can execute commands, call external services, access internal knowledge, and act through a non-human identity. Compromising one can give an attacker both information and an operating channel.

CrowdStrike presented this dual threat in its 2025 Threat Hunting Report, published during Black Hat USA on August 4, 2025. Its subsequent research has reinforced the warning. AI is lowering the cost of selected attack tasks while creating privileged systems that defenders cannot treat like ordinary software.

What CrowdStrike Actually Found

The central finding is not that AI invented new cybercrime, but that it makes familiar methods easier to scale and harder to contain.

The threat hunting findings were based on frontline investigations and intelligence covering more than 265 named adversaries. CrowdStrike said attackers were applying generative AI across social engineering, influence operations, fraudulent employment, and technical problem-solving.

The company highlighted FAMOUS CHOLLIMA, its name for a North Korea-linked operation involving fraudulent remote technology workers. CrowdStrike said it investigated more than 320 affected companies during the preceding 12 months. That represented a 220 percent increase from the prior period, according to the company.

These operations were more involved than sending polished résumés. CrowdStrike said operatives used generative AI throughout recruitment and employment. Reported uses included creating application materials, preparing for interviews, masking identities, and completing technical work after being hired.

A fraudulent worker who passes normal screening enters through an authorized account. The employer may provide a managed device, credentials, source-code access, and internal communication channels. That makes the operation an insider threat supported by deception, rather than a conventional external intrusion.

Generative AI helps connect the individual stages. It can rewrite a résumé for each opening, prepare answers, generate code, and maintain a consistent fictional background. However, CrowdStrike's evidence does not establish that AI independently conducted these operations. People still directed the campaigns and benefited from their access.

Other state-linked groups used the technology differently. CrowdStrike said Russia-linked EMBER BEAR applied generative AI to influence activity supporting pro-Russia narratives. Iran-linked CHARMING KITTEN reportedly used large language models to improve phishing material aimed at American and European targets.

The report also examined hands-on-keyboard intrusions, where an attacker manually interacts with a compromised environment. CrowdStrike found that 81 percent of those intrusions were malware-free during the observed period. Attackers instead relied on valid credentials, trusted tools, cloud services, and built-in administrative functions.

That statistic matters because many defenses still concentrate on detecting malicious files. A legitimate account using approved software may produce few traditional malware indicators. AI can help an attacker research the environment or interpret technical output without introducing a detectable payload.

Cloud intrusions added another layer of pressure. CrowdStrike reported a 136 percent increase during the first half of 2025 compared with all of 2024. The comparison covers periods of different lengths, so it should be read as an operational warning rather than a market-wide rate.

Cloud consoles contain identities, storage, secrets, and management controls. They also host many of the tools used to build and run AI applications. That concentration makes cloud access valuable even when the attacker never compromises an employee laptop.

The figures come from CrowdStrike's visibility into customer environments and investigations. They are not a census of every global intrusion. Vendor telemetry can identify meaningful patterns, but it also reflects the vendor's customer base, detection methods, and definitions.

That limitation does not erase the pattern. It establishes the right level of confidence. CrowdStrike observed attackers combining AI-assisted work with identity abuse, trusted services, and cloud access across real investigations.

Why This Google News Warning Matters Now

AI adoption is moving authority from visible human actions into automated workflows that many security teams cannot fully inventory.

The Google News headline captures a genuine reversal. Companies adopted AI to speed research, coding, customer support, and administrative work. Each connection that makes an agent useful can also increase the damage caused by manipulation or stolen access.

An AI agent is software that receives a goal, selects actions, and uses tools with limited human intervention. Unlike a conventional chatbot, it may interact with email, databases, browsers, code repositories, or cloud services. That ability turns a misleading input into a possible operational event.

Consider an agent that prepares sales briefings. It may read customer records, meeting transcripts, and internal documents. If an attacker manipulates its instructions, the agent might disclose confidential material or carry contaminated information into another system.

A coding agent creates a different exposure. It may inspect private repositories, run terminal commands, install packages, and submit changes. A compromised plugin or malicious instruction could exploit that access without resembling the malware delivery methods defenders already monitor.

The risk does not require a fully autonomous attacker. An adversary only needs to corrupt one input, steal one token, or exploit one vulnerable component. The trusted agent can then perform the next action using permissions that the organization granted legitimately.

This is why identity has become central. Machine identities include service accounts, tokens, application credentials, and other non-human access mechanisms. They often operate continuously, and their activity can blend into expected automation.

Human accounts usually have established controls around hiring, departures, authentication, and access reviews. Machine identities can multiply much faster. Teams may create them during experiments, leave them overprivileged, or fail to record who owns them.

Autonomous behavior further complicates monitoring. A human analyst can explain why they opened a file or changed a setting. An agent may choose a sequence dynamically, depending on its model output and the information it encounters.

Security teams therefore face two related questions. They must decide whether the identity was allowed to perform an action. They must also determine whether the agent was acting toward its intended goal.

Traditional access control answers the first question imperfectly. It rarely answers the second. An agent can make a harmful decision while using valid credentials and approved tools.

CrowdStrike's later findings strengthened this argument. Its 2026 threat report said activity by AI-enabled adversaries increased 89 percent year over year. The company also reported that attackers injected malicious prompts into legitimate generative AI tools at more than 90 organizations.

CrowdStrike measured an average eCrime breakout time of 29 minutes in 2025. Breakout time is the interval between initial access and lateral movement into another system. The fastest observed case took 27 seconds, according to the company.

Those numbers should not be interpreted as proof that most attacks are autonomous. CrowdStrike describes AI-enabled adversaries, a broader category that can include people using AI during selected stages. The distinction matters when organizations plan defenses or estimate near-term risk.

The operational lesson remains urgent. A review process measured in hours cannot reliably stop movement measured in minutes. A workflow that requires several manual approvals may fail when an attacker can reuse valid identities almost immediately.

AI can help defenders analyze signals at comparable speed. Yet automated defense also requires boundaries, evidence, and human escalation. Giving a security agent unlimited authority would reproduce the same privilege problem that creates risk elsewhere.

Attackers Use AI to Scale Trust Abuse

The most mature malicious uses of AI strengthen deception and workflow efficiency, rather than replacing attackers with independent machines.

The fraudulent-worker cases illustrate this pattern clearly. The attacker does not ask a model to breach a company from beginning to end. Instead, AI supports repeated tasks that previously consumed time or required additional people.

A language model can adapt application materials to a job description. It can translate messages, generate plausible explanations, and assist with unfamiliar programming work. Synthetic media may also support efforts to conceal the operator's identity during remote interviews.

Each capability improves scale. A group can pursue more roles, maintain more personas, and respond faster. The resulting access still arrives through business processes that companies designed for legitimate recruitment.

This makes the hiring system part of the security perimeter. Recruiters, hiring managers, IT administrators, and engineering leaders each see only one section of the process. Suspicious details may never reach the same reviewer.

The attack can also continue after onboarding. A worker with valid access can copy code, collect credentials, or route earnings toward a sanctioned regime. AI assistance helps the operator perform enough work to remain credible.

Defenders should avoid treating awkward video behavior or language mistakes as decisive proof. Those signals can harm legitimate candidates and are easy for attackers to adjust. Stronger controls connect identity verification, device provenance, access scope, and ongoing behavior.

Phishing shows the same economic effect. Generative AI can improve grammar, translate messages, and tailor lures using public information. It does not guarantee persuasion, but it reduces the effort needed to create acceptable variations.

Attackers can also use models for technical support. A less experienced operator may request scripting help or explanations of unfamiliar systems. This lowers some skill barriers without removing the need for access, judgment, testing, and operational discipline.

The outcome is an uneven capability increase. AI helps most where tasks are repetitive, language-heavy, or easy to verify. It remains less dependable when an intrusion demands original research, stable long-term planning, or precise decisions under uncertainty.

That distinction challenges dramatic predictions about autonomous hacking. Security leaders should prepare for faster assisted attackers before assuming reliable end-to-end autonomy. The assisted model is already sufficient to increase alert volume and compress response time.

Attackers also benefit from legitimate infrastructure. They can operate through cloud platforms, remote administration tools, collaboration services, and approved applications. These services provide scale and credibility while complicating simple blocking rules.

CrowdStrike's finding that 81 percent of hands-on-keyboard intrusions were malware-free fits this pattern. The adversary's advantage increasingly comes from appearing authorized. AI improves that appearance by supporting communication, research, and rapid adjustment.

Identity protection therefore matters more than detecting malicious code alone. Phishing-resistant authentication can reduce account takeover risk, although no authentication method solves fraudulent employment or stolen session tokens by itself.

Organizations also need shorter credential lifetimes and narrower permissions. A token that can read every repository or invoke every production tool creates unnecessary exposure. Agent access should follow the same least-privilege principle applied to human users.

Least privilege means granting only the access needed for a defined task. For agents, that access should also expire quickly and remain tied to an identifiable owner. Persistent shared credentials make attribution and containment much harder.

Security teams need evidence that connects prompts, tool calls, identity events, and resulting changes. Without that trail, analysts may see an approved account performing an approved action, but not the manipulation that caused it.

This is where knowledge governance intersects with cybersecurity. Organizations centralizing research, transcripts, and files in a personal knowledge base should understand which agents can retrieve that material. Search convenience should not silently become universal machine access.

The goal is not to stop employees from using AI. It is to keep experimentation from creating invisible identities and undocumented connections. Security teams cannot protect an agent that nobody has recorded.

AI Agents Turn Useful Automation Into a Target

The more authority an AI agent receives, the more valuable it becomes to an attacker and the more carefully its inputs require protection.

CrowdStrike said it observed threat actors exploiting vulnerabilities in tools used to build AI agents. Reported outcomes included unauthenticated access, credential theft, persistent access, malware deployment, and ransomware delivery.

The weakness may sit outside the model itself. An agent depends on orchestration software, APIs, plugins, data stores, cloud services, and identity systems. A flaw anywhere in that chain can expose the surrounding environment.

This system-level view is essential. Model testing alone cannot reveal a leaked token, an exposed development interface, or an overprivileged service account. Securing AI requires examining the complete application and its operational dependencies.

Prompt injection presents another route. It occurs when hostile content causes a model to follow unintended instructions. The content can appear in a webpage, document, email, tool response, or other material that an agent processes.

A direct prompt injection comes from the user. An indirect injection hides instructions in external content that the model later retrieves. The second form is especially difficult because useful agents are expected to read untrusted material.

The OWASP agent guidance treats prompt injection, excessive agency, sensitive information disclosure, and unsafe tool use as connected risks. An injected instruction becomes more dangerous when the affected agent has broad permissions.

Filters can reduce obvious attacks, but they cannot guarantee that a model separates every instruction from every piece of data. Natural language does not provide a dependable security boundary by itself.

The safer architecture assumes model output can be wrong or manipulated. It validates each high-impact action outside the model, limits accessible tools, and requires approval when consequences exceed a defined threshold.

An email assistant may draft messages automatically but require approval before sending externally. A coding agent may propose changes but lack direct production credentials. A support agent may read one customer's record without exporting the wider database.

These controls reduce autonomy, which exposes the central tradeoff. Businesses want agents because they can act without constant supervision. Security improves when consequential actions face predictable limits and verification.

The answer is not one universal approval dialog. Excessive prompts teach users to approve everything. Controls should reflect the action's reversibility, data sensitivity, destination, and potential reach.

Reading a public webpage carries less risk than deleting cloud resources. Drafting an internal summary differs from sending customer data to an external address. Security policies should encode those differences before the agent acts.

The United States National Institute of Standards and Technology recommends managing AI risks throughout design, deployment, and monitoring. Its AI risk framework emphasizes governance, measurement, and ongoing management rather than a single certification event.

That lifecycle approach suits agentic systems. An agent's behavior can change when teams replace its model, add a tool, modify a prompt, or connect another data source. A security review from launch day becomes outdated quickly.

Inventory is the necessary starting point. An organization should know which agents exist, who owns them, which models they use, and which identities authorize their actions. It should also record the information and tools each agent can reach.

The inventory must include unofficial deployments. Employees often connect consumer AI services to company data before a central team approves a platform. Blocking every experiment can drive that activity further from view.

A safer program offers approved paths with clear boundaries. Teams can test agents in isolated environments, use synthetic data, and request limited credentials. Security then becomes part of delivery instead of a final obstacle.

Runtime monitoring must look beyond model inputs. Analysts need records of retrieved information, tool selection, API calls, access changes, and external communication. They also need a way to suspend an agent immediately.

Agent owners should define expected behavior in measurable terms. A finance agent might read invoices from one repository and create drafts in one system. Access outside that pattern deserves investigation even if authentication succeeds.

Human oversight remains important, but humans cannot inspect every low-level action. The practical model combines machine-enforced limits, automated anomaly detection, and human review for uncertain or high-impact cases.

CrowdStrike has a commercial interest in expanding AI security spending. Its reports support products that govern identities, endpoints, cloud activity, and autonomous agents. That interest deserves acknowledgment when evaluating the company's framing.

At the same time, its core warning aligns with established security principles. Systems with sensitive data, broad permissions, and external inputs require strong isolation and monitoring. AI agents combine all three characteristics unusually often.

The unresolved issue is measurement. Public reports provide examples and selected telemetry, but the industry lacks a consistent denominator for agent compromise. Organizations still cannot easily compare incident rates across deployments or security architectures.

That gap creates room for both complacency and exaggeration. Some leaders may dismiss agent attacks as isolated demonstrations. Others may purchase broad controls without identifying which workflows actually create material exposure.

A defensible response begins with access and consequences. If an agent cannot reach sensitive information or perform consequential actions, prompt manipulation has limited value. If it controls production systems, every untrusted input deserves attention.

What Security Teams Should Watch Next

The next phase will be defined by three signals: verified agent intrusions, identity-aware controls, and credible measurements of defensive performance.

The first signal is evidence connecting a real compromise to an agent's decisions and permissions. Researchers have already documented vulnerable AI infrastructure and prompt manipulation. What matters next is whether incident reports show agents enabling lateral movement, data theft, or destructive actions at scale.

Detailed disclosure would strengthen CrowdStrike's argument. Useful reports should identify the initial input, affected identity, available tools, resulting action, and control failure. Vague references to an AI-related incident will not establish causation.

If public investigations continue finding only conventional credential theft near AI systems, the strongest autonomy claims will weaken. The infrastructure still requires protection, but the risk would remain closer to established cloud and application security.

The second signal is how quickly security platforms adopt identity-aware agent controls. CrowdStrike announced expanded protections across endpoints, browsers, software services, and cloud environments in March 2026. Other vendors are pursuing related discovery, governance, and runtime monitoring functions.

The important question is not how many products add an AI label. Buyers should ask whether a control can identify the human owner behind an agent, restrict tool use, rotate credentials, and preserve evidence across systems.

Open standards would improve portability. Organizations should not need separate identity models for every agent framework. Common records for authorization, tool calls, and delegated actions would make investigation and policy enforcement more consistent.

CrowdStrike joined an industry effort around open AI security research in July 2026. Its security alliance announcement emphasized shared models, testing tools, and community evaluation. Concrete benchmarks and interoperable controls will matter more than membership announcements.

If vendors expose consistent agent telemetry and enforcement points, the dual-threat thesis becomes more manageable. If controls remain proprietary and fragmented, attackers can exploit gaps between identity, model, and application monitoring.

The third signal is measurable defensive performance. Security agents promise faster triage, threat hunting, and response. Buyers need evidence showing detection quality, containment time, false-positive rates, and the consequences of automated mistakes.

Breakout time provides one useful pressure metric. CrowdStrike's reported average of 29 minutes leaves little room for a slow manual process. However, speed alone cannot determine whether an automated response is accurate or safe.

A system that isolates legitimate users too often creates operational harm. A system that produces fluent summaries without reliable evidence can waste analyst time. Defensive AI should therefore be evaluated against specific tasks and failure costs.

Independent testing will become increasingly important. Vendor demonstrations usually operate in controlled environments with selected data. Real security operations include incomplete telemetry, conflicting alerts, legacy systems, and business constraints.

Boards and executives should request a compact set of operational answers. They need to know how many agents exist, which ones hold consequential permissions, and how quickly the company can revoke their access.

Engineering teams need different details. They should know which inputs are untrusted, which actions receive external validation, and whether logs connect an agent's reasoning context to resulting tool calls.

Security teams must connect those views. An inventory without runtime evidence becomes a spreadsheet that ages quickly. Monitoring without ownership leaves analysts unable to decide whether unusual behavior is legitimate.

The Google News framing makes the story sound like a contest between offensive and defensive AI. The more consequential contest is between expanding machine authority and the controls surrounding it.

AI will continue helping attackers with language, research, and repetitive technical work. It will also help defenders process telemetry and respond faster. Neither outcome removes the need for identity controls, constrained permissions, and verifiable action records.

Organizations should start with one direct exercise. Select the agent with the broadest access, then trace every identity, data source, tool, and external destination it can use. Test what happens when one input becomes malicious.

Can the agent expose confidential data, change a production resource, or contact an external party without approval? Can the security team reconstruct each step and disable its credentials immediately? Those answers matter more than broad predictions about autonomous cyberwarfare.

CrowdStrike's warning deserves attention because it describes an exposure already forming inside ordinary business workflows. The practical response is neither panic nor unrestricted adoption. It is disciplined authority: inventory every agent, minimize every permission, validate consequential actions, and preserve evidence that investigators can trust.

Get started for free

A local first AI Assistant w/ Personal Knowledge Management

For better AI experience,

remio only supports Windows 10+ (x64) and M-Chip Macs currently.

​Add Search Bar in Your Brain

Just Ask remio

Remember Everything

Organize Nothing

bottom of page