CrowdStrike report: AI is rewriting rules of cybersecurity
A new report from the cybersecurity company CrowdStrike says that artificial intelligence is rewriting the rules of cybersecurity. The report describes a range of attacks that target AI systems and infrastructure. According to the report, threat actors are stealing credentials for commercial AI models, hijacking enterprise AI resources and abusing computing credits. The report groups these activities under the categories of LLM jacking and cost harvesting.
The report says LLM jacking involves attackers taking control of large language models, while cost harvesting involves abusing computing credits associated with those models. It also states that AI-assisted research is shortening the time between vulnerability disclosure and real-world attacks. In other words, the window between a vulnerability becoming known and an attack exploiting it is getting smaller. The report presents this as a consequence of AI tools helping attackers work more efficiently and find weaknesses faster.
The report's central claim is that AI has changed the threat environment for organizations using commercial models and enterprise AI resources. It indicates that these resources have become direct targets rather than just tools for attackers. The report also suggests that organizations need to account for these new attack patterns as they adopt AI. The report says the rules of cybersecurity are being rewritten as a result. These findings reflect a broader shift in which AI is affecting both the tools used in attacks and the systems being attacked.