ZDNET67%

AI is both a cyber weapon and a massive target, CrowdStrike warns 70%

By Charlie Osborne65%

8/3/2026, 10:52:06 AM

BS Summary: This article contains 26 faulty reasoning types, including Anecdotal, Pessimism Bias, and Post Hoc (False Cause), with Negativity Bias as the most egregious example at 49.8% saturation with 511 hits. Analysis detected 2,340 faulty-reasoning hits from 1,027 analyzed words, generating a BS Score of 56.1% and a BS Rank of 70% (8,301 of 27,360 articles). This article is worse (more manipulative) than 69.70% of the article peer group.

Artificial intelligence is increasingly "an adversary tool and target," researchers said, forcing businesses to rethink their defensive strategies in light of attack signals far outstripping what cybersecurity experts can manually handle. 
According to CrowdStrike's 2026 Threat Hunting Report, published on Monday, the same AI models, tools, and workflows that are giving businesses growth and productivity opportunities are being weaponized by cybercriminals in droves. 
Also: How Google used AI agents to find and fix 1,072 Chrome security bugs - in 60 days 
As corporate networks expand, endpoint devices are added, and new large language models (LLMs) are deployed to handle various workloads, organizations are also unwittingly creating larger "undefended" attack surfaces that can be exploited to steal data, obtain AI model access, conduct surveillance, and potentially even harvest computing power for their own ends. 
AI: The new weapon and target "AI is not just the tool or weapon that is being used, but it is also the attack surface," Adam Meyers, head of threat intel at CrowdStrike, commented. 
"We're seeing threat actors really adopt AI at the same speed that everybody else is." 
CrowdStrike's report said that the widespread adoption of artificial intelligence (much of it new and unproven) is increasing the sheer volume of signals that defenders have to sort through. 
Also: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it 
There are now 2.5 times as many AI agent-triggered leads for the firm's threat hunters to examine as there are manually driven leads, which CrowdStrike said "makes it more difficult for defenders to distinguish malicious activity from expected AI-driven behavior." 
Suspicious alerts and signals underscore AI-driven activity in the criminal world -- and the rapid speeds at which attacks are now being conducted. 
CrowdStrike gave a number of examples, including: 
Famous Chollima: A Democratic People's Republic of Korea (DPRK)-associated group is actively weaponizing trusted AI environments and tools to try to gain entry to companies working in cryptocurrency and the blockchain, using everything from AI-generated resumes to deepfake interviews. 
Cordial Spider, Snarky Spider: These groups use vishing to exfiltrate data from SaaS apps and compromise single sign-on accounts. 
In one case documented by the researchers, an attack shifted from account takeover to data theft in less than five minutes. 
LLMJacking: LLMJacking occurs when a threat actor gains access to keys or credentials used to access a company's AI models. 
Armed with access to these LLMs -- which are typically cloud-based -- threat actors can then steal data and wreak havoc, such as forcing the model to perform malicious tasks or those that demand high compute power, creating massive bills for the victim. 
For example, CrowdStrike said that in one campaign, the victim's LLM was used to generate close to 200,000 API requests in two minutes, "resulting in large-scale financial and operational impact." 
AI is mostly used by cybercriminals today to generate phishing and vishing material, payloads, and commands, streamlining their attack chains and potentially creating more convincing phishing schemes designed for initial access. 
Meyers said these creations are becoming more bespoke, with custom tools generated by AI and LLMs to manage different defense scenarios. 
Vulnerability windows vanish: More bad news for defenders 
Another concerning trend highlighted in the report is the shrinking window that human defenders -- and their tools -- have to respond between vulnerability discovery and exploitation. 
From January through June 2026, 88% of exploits detected by CrowdStrike were launched within 48 hours of a public proof-of-concept (PoC) code release. 
Also: Not just OpenAI - Anthropic says Claude's hacking spree 'falls short of ideal behavior' 
Some threat groups, such as China's Vault Panda and Genesis Panda, are keeping an even closer eye on new bugs: They developed working exploits for a critical vulnerability in a web application (React2Shell) within a day of disclosure. 
In these situations, AI goes both ways. 
Two out of three recently disclosed LPE exploits, CopyFail and Fragnesia (Dirty Frag being the third), were discovered by AI-assisted research, and the report said "threat actors wasted no time incorporating them into active operations." 
What does this mean for the enterprise and its cybersecurity teams? 
According to CrowdStrike, response times are going to become shorter and shorter -- no doubt due in part to the weaponization of AI. 
Also: Claude AI shared chats indexed by Google - see if your conversations were exposed 
"While this pattern predates the emergence of frontier AI models, the implementation of these systems is likely to compress vulnerability exploitation timelines by accelerating vulnerability discovery and exploit development," the researchers said. 
"This could, in turn, increase the pressure on defenders already struggling to keep pace." 
Your move 
AI can act as a shield, but as CrowdStrike's research revealed, it can also be a weapon. 
Also: Open weights vs. closed: An AI civil war's afoot, and the stakes are existential 
With the pressure caused by AI, defenders will be hard-pressed to retain control and secure the networks and endpoints they are responsible for, and so the team recommended that businesses adopt the following practices: 
Secure your AI applications and LLMs: With AI now embedded across multiple business environments, companies should enforce least-privilege principles, protect AI-related credentials, and monitor for suspicious LLM usage or cost spikes to reduce emerging business and operational risk. 
Identity is a primary attack surface: This issue existed before AI, but now, securing and verifying identities is even more important. 
Organizations should enforce phishing-resistant multifactor authentication, monitor access to corporate resources, and apply least privilege to human and non-human accounts. 
Tackle cross-domain blind spots and secure the software supply chain: Digital blind spots in the supply chain and in your own networks can be exploited. 
Telemetry, behavioral detection and analysis software, frequent patch cycles, and threat intelligence can reduce the risk of compromise. 
Be proactive: AI weaponization, moving at a speed we can't, is now forcing organizations to shift from a reactive to a proactive security stance. 
Investment, threat triage, and tackling the legacy security issues that threaten today's networks should all be handled quickly. 
By reducing the attack surface, you'll give your teams the breathing space to keep up. 
Article reasoning-pattern comparisonThis article: 7.0%Charlie Osborne: 1.7%ZDNET: 2.7%Confirmation Bias7.0%This article: 0.0%Charlie Osborne: 0.6%ZDNET: 1.2%Anchoring Bias0.0%This article: 14.2%Charlie Osborne: 5.3%ZDNET: 2.7%Availability Heuristic14.2%This article: 3.0%Charlie Osborne: 1.4%ZDNET: 0.9%Representativeness Heuristic3.0%This article: 0.0%Charlie Osborne: 0.5%ZDNET: 0.5%Hindsight Bias0.0%This article: 12.4%Charlie Osborne: 1.4%ZDNET: 2.7%Overconfidence Bias12.4%This article: 6.8%Charlie Osborne: 4.0%ZDNET: 3.4%Framing Effect6.8%This article: 5.6%Charlie Osborne: 2.2%ZDNET: 1.1%Loss Aversion5.6%This article: 5.7%Charlie Osborne: 1.4%ZDNET: 0.6%Status Quo Bias5.7%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Sunk Cost Effect0.0%This article: 3.2%Charlie Osborne: 1.3%ZDNET: 4.0%Optimism Bias3.2%This article: 15.7%Charlie Osborne: 2.8%ZDNET: 1.3%Pessimism Bias15.7%This article: 49.8%Charlie Osborne: 11.7%ZDNET: 4.5%Negativity Bias49.8%This article: 0.0%Charlie Osborne: 0.7%ZDNET: 1.3%Self-Serving Bias0.0%This article: 0.0%Charlie Osborne: 0.9%ZDNET: 0.3%Fundamental Attribution Error0.0%This article: 0.0%Charlie Osborne: 0.1%ZDNET: 0.0%Actor-Observer Bias0.0%This article: 0.0%Charlie Osborne: 0.2%ZDNET: 0.4%In-Group Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Out-Group Homogeneity Bias0.0%This article: 0.0%Charlie Osborne: 1.0%ZDNET: 2.8%Halo Effect0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Horn Effect0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Dunning-Kruger Effect0.0%This article: 5.0%Charlie Osborne: 1.8%ZDNET: 1.1%Recency Bias5.0%This article: 1.8%Charlie Osborne: 0.3%ZDNET: 0.3%Primacy Effect1.8%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Blind-Spot Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Ad Hominem0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Straw Man0.0%This article: 0.0%Charlie Osborne: 3.1%ZDNET: 3.9%Appeal to Authority0.0%This article: 2.3%Charlie Osborne: 0.6%ZDNET: 1.2%False Dilemma2.3%This article: 14.2%Charlie Osborne: 1.8%ZDNET: 0.6%Slippery Slope14.2%This article: 0.0%Charlie Osborne: 0.2%ZDNET: 0.2%Circular Reasoning0.0%This article: 12.3%Charlie Osborne: 3.5%ZDNET: 5.4%Hasty Generalization12.3%This article: 1.5%Charlie Osborne: 0.5%ZDNET: 0.4%Red Herring1.5%This article: 0.0%Charlie Osborne: 0.1%ZDNET: 0.5%Bandwagon0.0%This article: 3.5%Charlie Osborne: 2.4%ZDNET: 1.7%Appeal to Emotion3.5%This article: 3.3%Charlie Osborne: 0.3%ZDNET: 0.5%Begging the Question3.3%This article: 15.6%Charlie Osborne: 1.5%ZDNET: 1.4%Post Hoc (False Cause)15.6%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Tu Quoque0.0%This article: 0.0%Charlie Osborne: 0.3%ZDNET: 0.2%Burden of Proof0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Appeal to Nature0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.2%Composition/Division0.0%This article: 15.8%Charlie Osborne: 2.4%ZDNET: 4.2%Anecdotal15.8%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%No True Scotsman0.0%This article: 7.0%Charlie Osborne: 2.4%ZDNET: 1.9%Ambiguity (Equivocation)7.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Charlie Osborne: 0.1%ZDNET: 0.1%Middle Ground0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Personal Incredulity0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Special Pleading0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.1%Genetic Fallacy0.0%This article: 3.3%Charlie Osborne: 1.5%ZDNET: 1.0%Unattributed Quote3.3%This article: 1.9%Charlie Osborne: 0.1%ZDNET: 0.4%Quote-first Misdirection1.9%This article: 4.5%Charlie Osborne: 2.2%ZDNET: 5.3%Biased Writer Voice4.5%This article: 8.8%Charlie Osborne: 7.8%ZDNET: 2.9%Indoctrination8.8%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Charlie Osborne: 0.0%ZDNET: 0.0%Politically Right Leaning Bias0.0%This article: 3.7%Charlie Osborne: 1.1%ZDNET: 6.2%Attempt to Sell a Product or S…3.7%

1027 words analyzed.

Speakers

3speakers30%attributed speech717writer words
Selected voice

Adam Meyers

100%flagged-word coverage
49 attributed words16% of attributed speech95% writer coverage
0%35.0%70.0%Unattributed Quote+69.4 ptsWriter: 0.0%Adam Meyers: 69.4%69.4%Biased Writer Voice+67.7 ptsWriter: 1.7%Adam Meyers: 69.4%69.4%Indoctrination-12.6 ptsWriter: 12.6%Adam Meyers: 0.0%0.0%Attempt to Sell a Product -5.3 ptsWriter: 5.3%Adam Meyers: 0.0%0.0%Quote-first Misdirection-2.8 ptsWriter: 2.8%Adam Meyers: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.