The malicious use of AI has rapidly accelerated to the point where some threat groups have embedded the technology across their cyber operations, according to a report released Monday by CrowdStrike.
China-nexus actors Vault Panda and Genesis Panda have used AI to exploit critical vulnerabilities within 24 hours after a proof-of-concept was disclosed.
Meanwhile a North Korea-nexus group tracked as Stardust Chollima was able to inject a malicious npm package into 131 trusted Mastra AI frameworks in a supply-chain attack, according to CrowdStrike researchers.
“Exploitation windows have collapsed down to hours, and zero-day and n-day vulnerabilities are being weaponized faster than traditional patching cycles can keep up,” Adam Meyers, head of counter adversary operations at CrowdStrike, told Cybersecurity Dive.
The report confirms growing evidence that AI is enabling hackers to add considerable speed and scale to their attacks. Software vulnerabilities can be exploited much faster than security teams can patch. AI gives threat groups the ability to scale their campaigns well beyond hands-on-keyboard attacks by human operators.
About 48,000 common vulnerabilities and exposures were published in 2025, representing a 20% year-over-year increase. In June 2026, about 7,400 CVEs were published, nearly double from the same period a year ago. Meyers warned the pace of CVE disclosure will continue to increase in the near future.
“It’s not entirely unfeasible for a 10-times increase in the number of vulnerabilities over the next couple of years,” he said.
AI toolbox
The report also shows that AI is being used to create more sophisticated tooling used in these attacks.
“Adversaries are creating AI-generated scripts, payloads and commands, and building much more bespoke, custom tools for each intrusion,” Meyers said. “You can see artifacts from LLMs in that tooling, things like emojis, better documentation and error handling that adversaries likely would have skipped before.”
In recent months, AI has been used by a variety of state-linked and other threat groups to accelerate attacks.
A Chinese-speaking threat actor recently used DeepSeek to launch an autonomous threat campaign, according to a report by Palo Alto Networks. The hacker attempted to use Western tooling, including Claude Code. Ultimately the actor reverted to manual operations and was able to exploit critical vulnerabilities in n8n and Citrix NetScaler.
The Five Eyes warned in June that organizations needed to harden their networks and make other changes in preparation for AI-based attacks.