Wednesday, August 5, 2026 · U.S. Edition Today's Paper Latest Headlines
Advertisement SPONSORED
VANTAGE CAPITAL
Built for what comes next. Private banking for ambitious balance sheets.
Open an account
The Index Today.
Vol. III · No. 217 · Today's Front Page
Markets Pulse · live · what do these signals mean?
Uncategorized

CrowdStrike: Hackers Sent Nearly 200,000 AI Requests in Two Minutes in New Breed of Attack

CrowdStrike's 2026 Threat Hunting Report found hackers sent nearly 200,000 AI model requests in a single two-minute burst, while 88% of publicly disclosed vulnerabilities were exploited within 48 hours as AI accelerates both sides of the cyber arms race.

$▲ +0.0%MED 14s·CONF 80.00
$▲ +0.0%MED 14s·CONF 80.00
Execution price · last 6 hoursvia TimePay LPM
-6h-4h-2hnow
SettlementTimePay 30s spot·Cash $1.00·TPC 10 credits
CrowdStrike: Hackers Sent Nearly 200,000 AI Requests in Two Minutes in New Breed of Attack

Cybersecurity firm CrowdStrike’s 2026 Threat Hunting Report delivers a blunt verdict on the state of digital defense: artificial intelligence is no longer an emerging risk on the horizon, it is embedded across modern adversary operations right now. The report, drawn from frontline intelligence tracking more than 290 named adversary groups, documents attackers using AI simultaneously as a tool, a target, and a force multiplier, according to CrowdStrike’s press materials and coverage from eSecurity Planet.

The Numbers That Stand Out

Among the report’s most striking findings: one campaign sent nearly 200,000 AI model requests within a two-minute window, an automated abuse pattern that would be impossible for a human operator to replicate. In the first half of 2026, 88% of exploitation attempts against vulnerabilities with public proof-of-concept code began within 48 hours of that code’s release, with China-linked groups CrowdStrike tracks as Vault Panda and Genesis Panda launching attacks within just 24 hours of disclosure. Cloud-focused eCrime activity — credential theft, cryptomining, large-language-model abuse, and digital asset theft — surged 171% during the period, and detections triggered by AI agents themselves grew 2.5 times faster than detections triggered by human analysts, a sign of how much automated activity security teams now have to sift through.

Supply Chains Under Siege

The report singles out software supply chains as a particular weak point. DPRK-linked adversaries poisoned 131 trusted AI framework packages, embedding malicious code into tools developers assumed were safe because they came from reputable repositories. CrowdStrike found that 87% of identified software registry threats in the first half of 2026 involved malicious npm packages specifically, extending a trend security researchers have flagged for several years as open-source package ecosystems became an attractive target precisely because so much modern software, including AI tooling, depends on them.

Context: A Threat Landscape That Outpaced Its Defenders

This escalation didn’t happen overnight. Security researchers have warned since generative AI’s mainstream arrival in 2023 that the same models making white-collar work faster would eventually make cybercrime faster too. What’s new in 2026 is the shift from theoretical warning to measured behavior: Darktrace’s State of AI Cybersecurity 2026 report separately found hyper-personalized phishing is now the top concern for 50% of security professionals, followed by automated vulnerability scanning and exploit chaining at 45% and adaptive malware at 40%. The World Economic Forum’s Global Cybersecurity Outlook 2026 has flagged similar governance gaps, noting that while 77% of organizations now run generative AI somewhere in their security stack, only 37% have a formal policy governing how it’s used.

Two Ways to Read the Same Data

Security vendors like CrowdStrike have an obvious commercial interest in emphasizing how dangerous the threat landscape has become, and some independent researchers caution against treating vendor threat reports as neutral science — the same reports that document rising danger are also marketing material for the companies selling AI-powered defense tools. That said, the underlying exploitation-speed statistics are corroborated across multiple independent reports this year, including Moody’s cyber outlook forecast, which separately flagged growing AI threats and regulatory friction as a defining theme for 2026. The consensus across vendors, even accounting for self-interest, is that the gap between attack speed and defense speed has widened, not narrowed.

What It Means Going Forward

For enterprises, the practical takeaway is that patching cadences built around weekly or monthly cycles are now dangerously slow when 88% of exploited vulnerabilities are hit within 48 hours of a proof-of-concept surfacing. Expect more companies to adopt AI-driven automated patching and anomaly detection just to keep pace, even though that risks an arms race where both attackers and defenders lean more heavily on AI systems neither fully trusts. Regulators are also likely to use reports like this one to push the formal AI-governance policies that only 37% of organizations currently have, particularly as supply-chain poisoning incidents like the 131 compromised AI packages start showing up in downstream products used by ordinary consumers. Insurance underwriters that price cyber-risk policies are also watching these figures closely, since a 171% surge in cloud-focused eCrime activity and a near-doubling of the pace at which disclosed vulnerabilities get exploited both point toward higher expected claims, which could push premiums up across the board for companies that haven’t demonstrably hardened their AI infrastructure. CrowdStrike’s researchers say they expect the next report cycle to show even faster exploitation windows, given how quickly proof-of-concept code now propagates through both criminal forums and legitimate security research channels alike.

Opinion
Your Library 0
No articles purchased yet.
DZ
Demo User
ZZAZZ Member
TPC Balance
2,880TPC
Articles owned0
TimePay earned142 TPC
The Index Today.