Updated
Updated · ZDNet · Aug 3
CrowdStrike Warns 88% of Exploits Hit Within 48 Hours as AI Expands Attack Surface
Updated
Updated · ZDNet · Aug 3

CrowdStrike Warns 88% of Exploits Hit Within 48 Hours as AI Expands Attack Surface

3 articles · Updated · ZDNet · Aug 3

Summary

  • CrowdStrike said AI is now both a weapon and a target, with businesses exposing new attack surfaces as they deploy LLMs, agents and connected endpoints across corporate networks.
  • 88% of exploits detected from January through June 2026 were launched within 48 hours of public proof-of-concept code releases, showing how quickly attackers are moving as AI speeds discovery and exploit development.
  • Nearly 200,000 API requests hit one victim's LLM in two minutes in an LLMJacking campaign, while another attack moved from account takeover to data theft in under five minutes.
  • 2.5 times more AI agent-triggered leads than manual leads are now reaching CrowdStrike threat hunters, making it harder for defenders to separate malicious activity from normal AI-driven behavior.
  • CrowdStrike urged companies to lock down AI credentials, enforce least-privilege access and phishing-resistant MFA, and monitor for suspicious LLM use and cost spikes as response windows keep shrinking.

Insights

If attackers can hijack enterprise AI in minutes, are companies deploying agents faster than they can secure identities, tokens, and cloud keys?
When 88% of exploits follow proof-of-concept releases within 48 hours, what does effective defense look like in an AI-accelerated threat window?
As deepfake hiring scams, device-code phishing, and poisoned AI packages rise together, which hidden trust gap is most likely to break first?