A report released by CrowdStrike on Monday shows that the pace of malicious use of artificial intelligence (AI) has accelerated sharply, with some threat groups embedding AI technology throughout their entire cyber operations.

According to CrowdStrike researchers, China-linked actors Vault Panda and Genesis Panda exploited critical vulnerabilities using AI within 24 hours of proof-of-concept (PoC) disclosure. Meanwhile, the North Korea-linked group tracked as Stardust Chollima injected malicious npm packages into 131 trusted Mastra AI frameworks through supply chain attacks.

"The vulnerability exploitation window has shrunk to hours, and the weaponization speed of zero-day and n-day vulnerabilities has outpaced the ability of traditional patch cycles to respond," Adam Meyers, head of CrowdStrike's counter-adversary operations, told Cybersecurity Dive.

The report confirms growing evidence that AI is helping hackers significantly increase the speed and scale of attacks. Software vulnerabilities are being exploited far faster than security teams can patch them. AI enables threat groups to expand attack campaigns far beyond what manual keyboard operations by human operators could achieve.

Approximately 48,000 Common Vulnerabilities and Exposures (CVEs) were published in 2025, a 20% increase year-over-year. In June 2026, approximately 7,400 CVEs were published, nearly double the number from the same period last year. Meyers warned that the pace of CVE disclosures will continue to accelerate in the near future.

"A tenfold increase in vulnerabilities over the next few years is not entirely implausible," he said.

AI Toolbox

The report also shows that AI is being used to create more sophisticated attack tools.

"Attackers are creating AI-generated scripts, payloads, and commands, and building more customized proprietary tools for each intrusion," Meyers said. "Traces of large language models (LLMs) can be seen in these tools, such as emojis, more polished documentation, and error handling, which attackers might have previously overlooked."

In recent months, various state-linked threat groups and others have leveraged AI to accelerate attacks.

According to a report by Palo Alto Networks, a Chinese-speaking threat actor recently used DeepSeek to launch an autonomous threat campaign. The hacker had attempted to use Western tools, including Claude Code, but ultimately reverted to manual operations and successfully exploited critical vulnerabilities in n8n and Citrix NetScaler.

The Five Eyes alliance warned in June that organizations need to strengthen cyber defenses and make other adjustments to counter AI-based attacks.