Ethical Hacking News
AI systems are becoming increasingly attractive targets for cyber attackers, with a 89% surge in machine-assisted activity reported in 2025. As AI-powered attacks continue to evolve and become more sophisticated, it's clear that the dual role of AI as both attack tool and target is here to stay.
AI is being increasingly used by attackers to carry out sophisticated cyberattacks, with a 89% surge in machine-assisted activity reported in 2025.Criminals are stealing corporate credentials and accessing frontier-model APIs using AI-powered attacks like LLMjacking.Nation-state and financially motivated attackers are using AI throughout the attack chain, including creating fake companies and GitHub accounts.Supply-chain attacks targeting cryptocurrency and blockchain companies have also been reported, using malicious scripts hidden in legitimate-looking project files.The rapid evolution of AI-powered attacks has led to an increase in vulnerabilities being weaponized through the use of AI.The impact of these attacks on organizations is significant, with many struggling to keep pace with the rapidly evolving threat landscape.
The latest wave of cyberattacks has highlighted the dual role that artificial intelligence (AI) plays as both a weapon used by attackers and a high-value target. According to CrowdStrike, a leading security firm, AI is being increasingly used by adversaries to carry out sophisticated attacks, with a 89% surge in machine-assisted activity reported in 2025. This trend is expected to continue, with the company's annual Threat Hunting Report detailing various instances of AI-powered attacks.
One of the most notable examples cited in the report is the use of LLMjacking, where criminals steal corporate credentials to access frontier-model APIs. In another example, cost harvesting is used to deliberately inflate a victim's AI usage to run up its bill. A particularly egregious incident saw a token thief sending about 200,000 API requests in just two minutes.
CrowdStrike tracks more than 290 adversary groups, with several notable examples of nation-state and financially motivated attackers using AI throughout the attack chain. One such group, Famous Chollima, which operates under the Lazarus Group umbrella, demonstrated the most advanced AI usage during the second half of 2025 and first half of 2026. This group created "entire fake companies with AI-generated websites, GitHub accounts, and email infrastructure to support insider threat operations."
The report highlights another supply-chain attack in January and February targeting cryptocurrency and blockchain companies. In these attacks, malicious scripts were published on GitHub repositories that contained legitimate-looking project files alongside hidden, malicious scripts. When developers opened these repos, the malicious scripts automatically executed commands that gave Famous Chollima access to their environments.
Another notable example is Altered Spider, a financially motivated crew tracked by CrowdStrike as compromising more than 300 software dependencies in one day. This crew harvested credentials and secrets before pivoting into cloud environments for theft and extortion.
The report also highlights the increased use of AI-powered attacks by nation-state actors. For instance, China-linked groups such as Vault Panda and Genesis Panda launched attacks within 24 hours of vulnerability disclosure. In contrast, CrowdStrike argues that the traditional 30-day patch window is now obsolete, with organizations struggling to keep pace with the rapidly evolving landscape.
The rapid evolution of AI-powered attacks has led to an increase in vulnerabilities being weaponized through the use of AI. This has resulted in a surge in CVEs (Common Vulnerabilities and Exposures), with 48,200 reported in 2025 and over 43,000 already this year. June alone saw more than 7,600 software bugs reported and tracked through CVEs.
The impact of these attacks on organizations is significant, with many struggling to keep pace with the rapidly evolving threat landscape. As Adam Meyers, CrowdStrike's senior VP counter adversary division, noted, "AI is both the weapon and the target." AI is becoming an increasingly attractive attack tool, while also being targeted by attackers.
The rise of AI-powered attacks highlights the need for organizations to stay vigilant and keep pace with the rapidly evolving threat landscape. As the use of AI continues to grow in the enterprise, it is essential that organizations implement robust security measures to protect themselves against these types of attacks.
AI systems are becoming increasingly attractive targets for cyber attackers, with a 89% surge in machine-assisted activity reported in 2025. As AI-powered attacks continue to evolve and become more sophisticated, it's clear that the dual role of AI as both attack tool and target is here to stay.
Related Information:
https://www.ethicalhackingnews.com/articles/AI-Becomes-Both-Attack-Tool-and-High-Value-Target-Cyberattacks-on-Machine-Learning-Rise-89-in-Latest-Wave-ehn.shtml
https://www.theregister.com/cyber-crime/2026/08/03/ai-is-both-the-weapon-and-the-target-in-latest-wave-of-cyberattacks/5281534
https://cyberscoop.com/crowdstrike-annual-threat-hunting-report-2026/
https://cybersecuritynews.com/famous-chollima-apt-hackers-attacking-job-seekers/
https://cyberwebspider.com/cyber-security-news/famous-chollima-apt-hackers-attacking-job-seekers-and-organization-to-deploy-javascript-based-malware/
https://www.picussecurity.com/resource/blog/lazarus-group-apt38-explained-timeline-ttps-and-major-attacks
https://en.wikipedia.org/wiki/Lazarus_Group
Published: Mon Aug 3 02:51:56 2026 by llama3.2 3B Q4_K_M