CrowdStrike urges organizations to secure AI against threat actors

Threat actors are increasingly exploiting AI systems, development tools and software supply chains to launch faster and more sophisticated attacks, according to cybersecurity firm CrowdStrike.

In a recent online briefing on the company’s latest Global Threat Report, CrowdStrike head of counter adversary operations Adam Meyers said organizations can no longer treat AI solely as a productivity tool and must begin securing it as a critical part of their digital infrastructure. ‘Securing AI is absolutely critical,’ Meyers said. ‘The expanding AI attack surface is being targeted by threat actors, ‘he said.

He noted that cybercriminals are attacking AI from multiple angles-from abusing AI-powered chatbots to consume costly computing resources to exploiting vulnerabilities in AI infrastructure platforms to deploy ransomware.

He said the growing use of AI-assisted software development has also created new risks for organizations. As developers increasingly rely on AI coding assistants, Meyers said the technology automatically downloads software packages and dependencies in real time to complete programming tasks. While this accelerates development, Meyers warned it also creates opportunities for attackers to poison software repositories or compromise developer accounts, allowing malicious code to spread quickly across organizations.

‘If you ask AI to code something for you, it’s going to start pulling down packages that it thinks it needs,’ he said. ‘That is happening with complete automation, and people are often not stopping to inspect those packages.’

According to CrowdStrike, recent software supply chain attacks have affected repositories that collectively recorded tens of millions of downloads each week, illustrating how rapidly malicious code can proliferate once trusted development channels are compromised.

The company also highlighted the growing role of AI in offensive cyber operations.

Meyers said threat actors, particularly those linked to China, are leveraging AI to accelerate vulnerability research and exploit newly disclosed software flaws in record time.

He noted that Chinese cyber groups have invested heavily in weaponizing vulnerabilities over the past several years, with AI significantly reducing the time needed to develop working exploits. ‘As we’ve seen with AI, it is extremely capable of helping find and exploit vulnerabilities, especially when information about those vulnerabilities is already publicly available,’ he said.

CrowdStrike warned that exploitation windows have narrowed dramatically, with some critical vulnerabilities being weaponized within hours of public disclosure. This leaves organizations with little time to respond using traditional monthly patching cycles.

‘The month-long patch cycle is obsolete,’ Meyers said, adding that companies should move toward automated remediation, accelerated patch management, and stronger exposure management to prioritize the most critical vulnerabilities.

Beyond securing AI applications, organizations must also strengthen the governance surrounding AI deployments.

Meyers said companies should view AI models as interchangeable components, placing greater emphasis on building secure ‘harnesses’ and operational controls around them rather than relying solely on the capabilities of any single model.

He cited CrowdStrike’s own experience, where applying the appropriate framework significantly improved the accuracy of AI-assisted vulnerability research by reducing false positives and producing more reliable results.

Open-weight AI models will also play an increasingly important role, he said, as organizations seek lower-cost alternatives to proprietary frontier models while maintaining flexibility to deploy AI securely for specific business functions.

Looking ahead, CrowdStrike expects more domain-specific AI models designed for specialized tasks, offering greater consistency and more predictable outputs.

The company urged organizations to complement AI adoption with comprehensive threat visibility, managed threat hunting, and stronger identity protection to prevent attackers from moving from compromised developer environments into enterprise cloud systems.

‘Threat actors continue to evolve and find new ways to attack,’ Meyers said. ‘Organizations need stronger guardrails, better intelligence and the right security controls to stay ahead.’ As AI becomes deeply embedded across enterprise operations, CrowdStrike said securing the technology itself must become as important as using it to improve productivity, warning that the organizations that fail to protect their AI environments could inadvertently provide cybercriminals with powerful new attack vectors.

Leave a Reply

Your email address will not be published. Required fields are marked *