翻訳待ち:AI is both a cyber weapon and a massive target, CrowdStrike warns
AI サービスが一時的に利用できないため、復旧後に翻訳を補完します。ソース概要:The same AI tools triggering suspicious alerts are being attacked by cybercriminals in droves.
AI サービスが一時的に利用できないため、復旧後に翻訳を補完します。
Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways CrowdStrike warns AI is both a target and a weapon. LLMJacking made nearly 200,000 API calls in two minutes. Malicious AI exploits flaws faster than defenders can patch them.Artificial intelligence is increasingly "an adversary tool and target," researchers said, forcing businesses to rethink their defensive strategies in light of attack signals far outstripping what cybersecurity experts can manually handle. According to CrowdStrike's 2026 Threat Hunting Report, published on Monday, the same AI models, tools, and workflows that are giving businesses growth and productivity opportunities are being weaponized by cybercriminals in droves. Also: How Google used AI agents to find and fix 1,072 Chrome security bugs - in 60 daysAs corporate networks expand, endpoint devices are added, and new large language models (LLMs) are deployed to handle various workloads, organizations are also unwittingly creating larger "undefended" attack surfaces that can be exploited to steal data, obtain AI model access, conduct surveillance, and potentially even harvest computing power for their own ends. AI: The new weapon and target "AI is not just the tool or weapon that is being used, but it is also the attack surface," Adam Meyers, head of threat intel at CrowdStrike, commented. "We're seeing threat actors really adopt AI at the same speed that everybody else is." CrowdStrike's report said that the widespread adoption of artificial intelligence (much of it new and unproven) is increasing the sheer volume of signals that defenders have to sort through. Also: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced itThere are now 2.5 times as many AI agent-triggered leads for the firm's threat hunters to examine as there are manually driven leads, which CrowdStrike said "makes it more difficult for defenders to distinguish malicious activity from expected AI-driven behavior." Suspicious alerts and signals underscore AI-driven activity in the criminal world -- and the rapid speeds at which attacks are now being conducted. CrowdStrike gave a number of examples, including: Famous Chollima: A Democratic People's Republic of Korea (DPRK)-associated group is actively weaponizing trusted AI environments and tools to try to gain entry to companies working in cryptocurrency and the blockchain, using everything from AI-generated resumes to deepfake interviews. Cordial Spider, Snarky Spider: These groups use vishing to exfiltrate data from SaaS apps and compromise single sign-on accounts. In one case documented by the researchers, an attack shifted from account takeover to data theft in less than five minutes. LLMJacking: LLMJacking occurs when a threat actor gains access to keys or credentials used to access a company's AI models. Armed with access to these LLMs -- which are typically cloud-based -- threat actors can then steal data and wreak havoc, such as forcing the model to perform malicious tasks or those that demand high compute power, creating massive bills for the victim. For example, CrowdStrike said that in one campaign, the victim's LLM was used to generate close to 200,000 API requests in two minutes, "resulting in large-scale financial and operational impact."AI is mostly used by cybercriminals today to generate phishing and vishing material, payloads, and commands, streamlining their attack chains and potentially creating more convincing phishing schemes designed for initial access. Meyers said these creations are becoming more bespoke, with custom tools generated by AI and LLMs to manage different defense scenarios. Vulnerability windows vanish: More bad news for defenders Another concerning trend highlighted in the report is the shrinking window that human defenders -- and their tools -- have to respond between vulnerability discovery and exploitation. From January through June 2026, 88% of exploits detected by CrowdStrike were launched within 48 hours of a public proof-of-concept (PoC) code release. Also: Not just OpenAI - Anthropic says Claude's hacking spree 'falls short of ideal behavior'Some threat groups, such as China's Vault Panda and Genesis Panda, are keeping an even closer eye on new bugs: They developed working exploits for a critical vulnerability in a web application (React2Shell) within a day of disclosure. In these situations, AI goes both ways. Two out of three recently disclosed LPE exploits, CopyFail and Fragnesia (Dirty Frag being the third), were discovered by AI-assisted research, and the report said "threat actors wasted no time incorporating them into active operations." What does this mean for the enterprise and its cybersecurity teams? According to CrowdStrike, response times are going to become shorter and shorter -- no doubt due in part to the weaponization of AI. Also: Claude AI shared chats indexed by Google - see if your conversations were exposed"While this pattern predates the emergence of frontier AI models, the implementation of these systems is likely to compress vulnerability exploitation timelines by accelerating vulnerability discovery and exploit development," the researchers said. "This could, in turn, increase the pressure on defenders already struggling to keep pace." Your move AI can act as a shield, but as CrowdStrike's research revealed, it can also be a weapon. Also: Open weights vs. closed: An AI civil war's afoot, and the stakes are existentialWith the pressure caused by AI, defenders will be hard-pressed to retain control and secure the networks and endpoints they are responsible for, and so the team recommended that businesses adopt the following practices: Secure your AI applications and LLMs: With AI now embedded across multiple business environments, companies should enforce least-privilege principles, protect AI-related credentials, and monitor for suspicious LLM usage or cost spikes to reduce emerging business and operational risk. Identity is a primary attack surface: This issue existed before AI, but now, securing and verifying identities is even more important. Organizations should enforce phishing-resistant multifactor authentication, monitor access to corporate resources, and apply least privilege to human and non-human accounts.Tackle cross-domain blind spots and secure the software supply chain: Digital blind spots in the supply chain and in your own networks can be exploited. Telemetry, behavioral detection and analysis software, frequent patch cycles, and threat intelligence can reduce the risk of compromise. Be proactive: AI weaponization, moving at a speed we can't, is now forcing organizations to shift from a reactive to a proactive security stance. Investment, threat triage, and tackling the legacy security issues that threaten today's networks should all be handled quickly. By reducing the attack surface, you'll give your teams the breathing space to keep up.