Aug 3, 2026
Enterprise

CrowdStrike 2026 Global Threat Report flags direct attacks on enterprise AI

CrowdStrike says attackers are abusing AI tools and moving faster, leaving security teams less time to validate and contain intrusions.

Wei-Lin Zhao

By Wei-Lin Zhao · AI Correspondent

· 3 min read

CrowdStrike 2026 Global Threat Report flags direct attacks on enterprise AI
Photo: SiliconANGLE

CrowdStrike’s 2026 Global Threat Report, released Feb. 24, says enterprise AI has become both an accelerant for attackers and a target in its own right. The cybersecurity vendor reported malicious-prompt abuse at more than 90 organizations, alongside attacks on AI development platforms and trusted-looking AI servers used to intercept sensitive data.

The report also puts numbers on a separate but related problem: the time attackers need to spread after getting in. CrowdStrike said average eCrime breakout time, its measure of movement from initial access to lateral movement, fell to 29 minutes in 2025. Its fastest observed case took 27 seconds. No funding, revenue or headcount figures were part of the release.

These are CrowdStrike’s own telemetry and intelligence findings, drawn from its threat hunters and analysts tracking more than 280 named adversaries. The supplied evidence does not independently verify the incident counts, their scope across all organizations, or the extent to which AI caused the reported changes.

How are attackers targeting AI systems?

CrowdStrike said attackers injected malicious prompts into legitimate generative AI tools at more than 90 organizations, producing commands intended to steal credentials and cryptocurrency. It also reported vulnerabilities in AI development platforms being used to establish persistence and deploy ransomware.

A third reported technique involved malicious AI servers that impersonated trusted services to capture sensitive information. In a later Threat Hunting Report summarized by SiliconANGLE, CrowdStrike also described a honeypot payload carrying a malicious Model Context Protocol server configuration. The payload was designed to read a parent process’s environment variables and send configuration data to an external webhook. That example shows a specific observed configuration-exfiltration attempt; it does not establish a general exposure outcome for all such systems.

CrowdStrike reported an 89% year-over-year rise in operations by AI-enabled adversaries. It said the technology was used in activities including reconnaissance, credential theft and evasion. Separately, the company said zero-day vulnerabilities exploited before public disclosure increased 42%.

Why do the timing metrics matter?

Breakout time and the disclosure-to-exploitation interval are different clocks. Breakout time starts after an attacker has obtained initial access and measures lateral movement. The exploitation window measures how long it takes attackers to adopt a vulnerability after its details become public. Both trends reduce time for detection, validation, containment and remediation, but neither proves that every disclosed vulnerability is exploited immediately.

CrowdStrike’s recommended response is to prioritize exposures that are reachable and exploitable, rather than work from severity scores alone. The company also calls for continuous validation of attack paths, tighter identity controls and faster detection-to-containment workflows. For operators, the implication is to decide in advance which exposures and identity events justify containment, rather than wait for a conventional remediation queue to work through them.

Anthropic has made a similar argument about defensive use of advanced models. In April, it launched Project Glasswing with CrowdStrike and other partners, saying its unreleased Claude Mythos Preview had found thousands of high-severity vulnerabilities and would be used in defensive security work. Those performance claims come from Anthropic and have not been independently validated in the supplied evidence.

This story draws on original reporting from SiliconANGLE.

More from Enterprise

All Enterprise →