โŒ

Normal view

AI is 'both the weapon and the target' in latest wave of cyberattacks

3 August 2026 at 09:01
AI is becoming both an attack tool and a high-value target, with attacks by AI-enabled adversaries rising 89 percent in 2025, according to CrowdStrike. The security firm's annual Threat Hunting Report details criminal gangs and nation states using AI throughout the attack chain. Attackers are also targeting organizations' AI infrastructure and poisoning popular software packages to compromise their users. "AI is both the weapon and the target," CrowdStrike counter adversary division senior VP Adam Meyers told reporters. "AI is a high-value attack surface, and it's being used by more and more threat actors." These attacks include LLMjacking, in which criminals steal corporate credentials to access frontier-model APIs, and cost harvesting โ€“ deliberately inflating a victim's AI usage to run up its bill. In one campaign, CrowdStrike documented a token thief sending about 200,000 API requests in just two minutes. The security vendor's threat hunting team now tracks AI agent-triggered leads at 2.5x the rate of human-triggered threats, and Meyers said this increased volume remains true across both government-backed goons and financially motivated criminals. CrowdStrike tracks more than 290 adversary groups, having added about ten this year. Of the 290, a North Korean crew it tracks as Famous Chollima โ€“ a sub-unit operating under the Lazarus Group umbrella and best known for its fake IT worker scams โ€“ "demonstrated the most advanced AI usage" over the second half of 2025 and first half of 2026, according to the report. This government-backed crew created "entire fake companies with AI-generated websites, GitHub accounts, and email infrastructure to support insider threat operations," the authors wrote. AI supply-chain compromise was the second most common MITRE ATLAS technique used by attackers to gain initial access, and Famous Chollima's campaign targeting AI-focused development environments "was one of the most sophisticated examples of this technique in practice," the report noted. This included a supply-chain attack in January and February targeting cryptocurrency and blockchain companies. In these attacks, the Norks published trojanized repositories, primarily hosted on GitHub, that contained legitimate-looking project files alongside hidden, malicious scripts. When developers opened these repos, malicious scripts automatically executed commands that gave Famous Chollima access to their environments. "AIs themselves are being targeted through that supply chain and through the CI/CD pipelines that they're dependent on," Meyers said. Threat hunters suspect another Lazarus Group offshoot, tracked as Stardust Chollima or Sapphire Sleet, was behind the March Axios supply chain attack. Last week, Amazon attributed four npm compromises over the past 18 months to the same North Korean crew. Meanwhile, a financially motivated crew tracked by CrowdStrike as Altered Spider and elsewhere as TeamPCP targeted developers' AI tools, compromising more than 300 software dependencies in one day. It harvested credentials and secrets before pivoting into cloud environments for theft and extortion. Altered Spider "hits the endpoint in seconds and within minutes, they're inside of the cloud," Meyers said. "It gives you a sense of how quickly they can move throughout that environment, and this is all tied again to software supply chains." Patching window slams shut CrowdStrike argues that AI is helping attackers exploit newly disclosed vulnerabilities at machine speed. From January to June, 88 percent of the exploitation observed by CrowdStrike using public proof-of-concept (PoC) code occurred within 48 hours of the code's release. The company said China-linked groups such as Vault Panda and Genesis Panda moved even faster, launching attacks within 24 hours of disclosure. "Vulnerabilities are weaponized through the use of AI," Meyers said. "This is creating a rich ecosystem of vulnerabilities for attackers to use against various systems, and what this really means is that the 30-day patch window, which frankly, was aspirational, is completely obsolete. We're down to 24-hour, 48-hour patch cycles, and organizations are really struggling under that." Meanwhile, as anyone who follows Microsoft's Patch Tuesday โ€“ or any other software vendors' vulnerability disclosures over the past few months โ€“ knows, AI is also really good at finding bugs in code. This means more CVEs and more patching for sysadmins racing to fix flaws before miscreants reverse-engineer the updates and develop exploits. "In 2025, there were something like 48,200 CVEs that were registered," Meyers said. "We're already, as of last week, at 43,000 for this year. We're not even into August yet, and we're already coming very close to the number from last year." June alone saw more than 7,600 software bugs reported and tracked through CVEs, he added. "The vulnerability ecosystem is going to be the big story for the next couple of months." ยฎ

Europol flags 4,340 'horrific' URLs linked to The Com

24 July 2026 at 22:20
Europol and its partners' investigators flagged 4,340 โ€œhorrificโ€ URLs for removal over several weeks in June and July as part of an ongoing crackdown on The Com (short for community), a loosely knit network of online groups whose young members participate in a range of illicit activities. These range from hacking, swatting, and digital extortion to real-life shootings, stabbings, and other physical violence. Europolโ€™s recent Referral Action Days, aimed at disrupting The Comโ€™s online ecosystem and stopping the spread of its propaganda, is part of the larger Project Compass operation. Project Compass began in 2025, and its partner law-enforcement agencies span the US, UK, and EU member states. Investigators from Belgium, Finland, Hungary, Ireland, Luxembourg, the Netherlands, Portugal, Spain, and Sweden participated in the Referral Action Days during June and July. Various groups linked to The Com post content online to recruit members and groom young victims using social media, gaming platforms, and messaging apps. โ€œThe more extreme and harmful the content a user or group can produce or extort, the higher their status within the online community,โ€ according to Europol. โ€œThese acts are often livestreamed on social media platforms, where online bystanders cheer them on, and later saved and disseminated.โ€ The URLs flagged for removal during this latest push to disrupt The Comโ€™s recruiting activities included โ€œviolent videos and images depicting self-harm, suicide, child sexual abuse material (CSAM), animal cruelty, and violent attacks,โ€ the international cops said. This, the European cops say, includes so-called blood walls, which are paintings made with blood that display the extorterโ€™s alias and group affiliation, and cut-signs, where the victims are forced to carve the extorterโ€™s name into their bodies. It also includes videos of street attacks and arson, plus manuals on how to commit these violent attacks, along with instructions on grooming and extorting vulnerable minors, and conducting doxxing and swatting. Europol says its European Counter Terrorism Centre has received โ€œhundredsโ€ of requests from member states and others over the past two years to help investigate crimes linked to The Com. It describes the online network as a โ€œglobal threat, particularly concerning minors as both victims and perpetrators.โ€ Last year, both the UK and US issued similar warnings about a subset of The Com that recruits children and teens for contract shootings, kidnappings, and other real-life violent crimes. In July 2025, the FBI said that In Real Life (IRL) Com had become increasingly brazen in its swat-for-hire and violence-as-a-service solicitations. The FBI's alert followed a similar notice from the UK National Crime Agency about a "deeply concerning" trend of The Com recruiting teenage boys to commit a range of criminal acts, from cyber fraud and ransomware to child sexual abuse.ยฎ

โŒ