One Attacker Fired Off 200,000 AI Requests in Two Minutes, CrowdStrike Finds
Cybersecurity

One Attacker Fired Off 200,000 AI Requests in Two Minutes, CrowdStrike Finds

CrowdStrike's 2026 Threat Hunting Report shows AI has moved from a novelty in adversary toolkits to standard operating equipment, compressing the time between vulnerability disclosure and exploitation to under two days.

PublishedAugust 23, 2026
Read time5 min read
Share

The Speed Problem AI Just Created

CrowdStrike's 2026 Threat Hunting Report, released August 3, puts a number on something most security teams already felt happening: the gap between a vulnerability going public and an attacker using it has collapsed. The report found that 88 percent of vulnerabilities with a public proof-of-concept were exploited within 48 hours of release, and specific China-nexus groups, tracked as VAULT PANDA and GENESIS PANDA, launched working attacks within 24 hours of disclosure. That is not a research team working overtime. That is automated tooling doing in hours what used to take a skilled team days to weaponize.

The scale example CrowdStrike highlights is the one worth sitting with: a single LLMJacking campaign, where an attacker abuses stolen credentials to run workloads on someone else's AI infrastructure, generated nearly 200,000 API requests in two minutes. Adam Meyers, CrowdStrike's head of counter adversary operations, framed the shift plainly, saying AI is now embedded in modern adversary operations and is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend. The report's title captures the same point: the exploitation window is closing as AI use accelerates on the attacker side.

Fake Companies Built Entirely by AI

The report's most striking single finding involves FAMOUS CHOLLIMA, a DPRK-nexus group that used AI to construct entire fake companies as cover for operations, complete with AI-generated websites, GitHub accounts, and email infrastructure supporting the front. Building that kind of convincing infrastructure used to require real time and real operational budget, which naturally limited how many fronts a group could maintain simultaneously. AI generation removes that constraint, letting a group stand up multiple credible-looking fronts in parallel at a fraction of the previous cost, each one available for social engineering, recruitment scams, or supply chain infiltration.

This connects directly to a separate supply chain finding in the same report: 87 percent of identified software registry threats in the first half of 2026 involved malicious npm packages, and one campaign, tracked as ALTERED SPIDER, compromised more than 300 software dependencies in a single day. CrowdStrike's framing is direct about why this matters beyond the statistic itself, noting that malicious packages can reach hundreds of thousands of systems within hours of publication, a reach that fake AI-generated maintainer identities and infrastructure make easier to sustain without detection.

Detection Is Shifting to Machine Speed Too

The report's defensive-side data point deserves equal attention: AI agent-triggered detection leads grew at 2.5 times the rate of human-triggered leads. That framing works two ways depending on how a security team reads it. On one hand, it shows AI-assisted detection genuinely surfacing more threats than manual hunting alone ever could, which is a real capability gain. On the other hand, it is also a signal that the volume of automated attacker activity has grown enough that automated detection is now the only realistic way to keep pace with it, because human analysts alone cannot triage at that scale.

CrowdStrike separately reported more than 14 million daily detection leads flowing through its analysis pipeline and more than 36,000 annual customer notifications and alerts generated from that volume. Numbers at that scale only make sense with AI-assisted triage sitting between raw detections and the humans who ultimately decide what needs action. Security leaders who have not yet invested in AI-assisted triage on their own side are effectively asking human analysts to compete at manual speed against attacker tooling that has already moved past it.

What Faster Exploitation Means for Patch Governance

A 48-hour median exploitation window changes what a reasonable patch SLA looks like. Monthly patch cycles, still the default at many enterprises, were designed for a threat landscape where researchers, criminal groups, and nation-state actors needed real time to build a working exploit from a disclosed vulnerability. That assumption no longer holds for a meaningful share of disclosures, particularly ones that ship with a public proof-of-concept attached, which is now functionally a starting kit rather than a research artifact. Waiting for the next scheduled patch window on a PoC-equipped CVE is a bet against odds that have shifted firmly against the defender.

This does not mean every patch needs same-day deployment, which would be operationally unrealistic and would burn credibility for the genuinely urgent cases. It means triage criteria need updating: any disclosure that ships with a public proof-of-concept, or that affects internet-facing infrastructure, should move into an expedited lane measured in hours, not the standard monthly lane. Security leaders should ask their patch management team this quarter whether that triage split already exists formally, or whether it currently depends on someone noticing the right CVE in a crowded weekly bulletin and deciding informally to move faster.

The Governance Gap Around AI Infrastructure Itself

CrowdStrike's finding that AI systems have become targets in their own right, not just tools attackers use, deserves a governance response separate from the exploitation-speed conversation. LLMJacking campaigns specifically abuse stolen credentials to run unauthorized workloads on AI infrastructure, meaning any enterprise running its own AI models or paying for AI API access carries a cost-and-abuse exposure that traditional security monitoring was not built to catch. A finance team watching a cloud bill will notice a spike eventually. A security team watching authentication logs specifically for AI service credentials will notice it much sooner, before the bill arrives.

The decision this puts on the table is whether AI credential management currently gets the same rigor as production database credentials or cloud infrastructure keys, categories where most enterprises already have mature rotation and monitoring practices. For many organizations, API keys for AI services were provisioned quickly during rapid adoption over the past two years and have not been through the same access review process since. CrowdStrike's data suggests that gap is now actively being probed. Closing it belongs on the same roadmap as the patch triage work, not treated as a separate, lower-priority initiative for later in the year.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#crowdstrike#threat-hunting-report#llmjacking#famous-chollima#altered-spider#patch-management#npm