Cyberattacks are getting faster as AI helps hackers scale

Companies are getting less time to respond to cyber threats as attackers use AI, automation and increasingly aggressive tactics to exploit vulnerabilities, compromise software and move through cloud environments.

A new threat hunting report from cybersecurity firm CrowdStrike found that 88% of vulnerabilities with a publicly available proof of concept were exploited within 48 hours during the first half of 2026. China-nexus groups VAULT PANDA and GENESIS PANDA were even faster, launching attacks within 24 hours of disclosure.

The numbers show how quickly the gap between a vulnerability becoming public and being actively exploited is closing. A company that once had days to assess a newly disclosed flaw may now have to act within hours.

Article continues after this advertisement

Threat actors are using AI to generate payloads and shell commands, target AI infrastructure and abuse enterprise large language models. In one campaign observed by CrowdStrike, attackers sent almost 200,000 requests to an AI model in two minutes.

That kind of activity is difficult to achieve manually at the same scale. AI gives attackers a way to automate parts of their operations, allowing them to generate more activity without requiring a person to handle every step.

The report also found that AI agent-triggered detection leads grew 2.5 times faster than human-triggered leads, giving security teams more activity to investigate as automated systems become more common in attacks.

The AI systems themselves are also becoming targets.

Article continues after this advertisement

CrowdStrike identified a campaign attributed to the DPRK-nexus group STARDUST CHOLLIMA that injected a malicious npm package into 131 trusted Mastra AI framework packages. During the first half of 2026, 87% of the software registry threats identified by the company involved malicious npm packages.

Another eCrime group, ALTERED SPIDER, compromised more than 300 software dependencies in a single day to steal credentials and move into cloud environments.

The attacks illustrate a broader problem with the rapid adoption of AI. Companies are not simply adding another application to their existing infrastructure. AI systems depend on frameworks, software packages, cloud services, credentials and other components that create additional opportunities for attackers.

Article continues after this advertisement

Cloud-conscious eCrime activity increased 171% during the first half of 2026, with attackers using cloud infrastructure for credential theft, cryptomining, large language model abuse and digital financial asset theft.

Authentication systems are another increasingly attractive target. Vishing intrusions doubled during the same period, while monthly device-code phishing attempts increased 15 times. In one incident cited by the report, the eCrime group SNARKY SPIDER went from compromising an account to stealing data in less than five minutes.Attackers can exploit newly disclosed vulnerabilities within a day, compromise software dependencies at scale and move through compromised accounts in minutes.

AI does not create every one of those threats, but it gives attackers another way to increase their speed and scale. It can automate work that would otherwise take human operators more time, while AI adoption itself is expanding the number of systems and dependencies that need to be secured.

As CrowdStrike head of counter adversary operations Adam Meyers put it, organizations need to secure AI as aggressively as they adopt it. The challenge is that the attackers are already using the technology to move faster, leaving security teams with an increasingly narrow window to catch up.