Cybercriminals are now deploying artificial intelligence as a routine part of their operations, from creating malicious code to running large-scale attack infrastructure, according to new research from Cisco Talos and CrowdStrike released during the Black Hat USA conference. The studies draw on recovered prompt logs, captured attack tools, and intercepted conversations between threat actors to show how AI has moved from experimental to everyday use in cybercrime. Sophisticated groups are leveraging AI to rapidly construct exploits and manage their operations, while attackers are also targeting AI systems themselves through supply chain compromises and prompt-based manipulation.

The CrowdStrike report reveals that 88% of observed exploitation of vulnerabilities with a public proof-of-concept happened within 48 hours of that proof-of-concept's release during the first half of 2026. Two separate Chinese advanced persistent threat groups exploited critical vulnerabilities within a single day of public proof-of-concept availability. Cloud-focused criminal activity jumped 171% as adversaries carried out credential theft, cryptomining, abuse of large language models, and digital financial asset theft. During the same period, 87% of identified software registry threats involved malicious npm packages, reflecting attackers' preference for JavaScript's scale and dependency chains. Vishing intrusions doubled in the first half of 2026, while cybercrime group Altered Spider compromised more than 300 software dependencies in one day to harvest credentials and move into cloud environments. After the React2Shell vulnerability disclosure, CrowdStrike responded to over 800 hunting leads across more than 80 victims in just four days.

The Cisco Talos researchers write that threat actors frequently bypass AI guardrails with basic social engineering claims—such as stating "this is authorised testing" or "I'm asking this as part of a capture the flag exercise"—that convince most models to comply. Analysis of prompt logs related to Claude Code, CodeX, Cursor, and Gemini showed this vulnerability was widespread across platforms, not limited to a single model. The report documents real-world cases of attackers abusing AI systems to construct a bulk-mail validation service processing tens of millions of email records, adapting the React2Shell vulnerability into a credential-harvesting pipeline, developing DDoS infrastructure targeting Android TVs, and supporting cryptocurrency theft operations. "AI is now embedded in modern adversary operations," says Adam Meyers, head of counter adversary operations at CrowdStrike. "It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend."

The reports indicate that attacker tradecraft is shifting away from traditional code-based exploits toward prompt-based manipulation of large language models, with malicious prompts embedded in shared text, video, or image files to hijack AI-based assistants. North Korean cybercrime group Stardust Chollima used stolen maintainer credentials in March 2026 to compromise the Axios npm package and deliver platform-specific variants of their ZshBucket malware, then in June 2026 injected a malicious npm package as a dependency into at least 131 Mastra AI framework packages. This demonstrates that trusted AI building blocks are becoming targets in supply chain attacks. Comprehensive industry-wide data remains limited because evidence of AI abuse is often difficult to identify through traditional security telemetry, the Cisco Talos report notes. The researchers urge enterprises to strengthen detection, prioritization, and their own use of AI platforms and agents to handle the growing volume of alerts and vulnerabilities.

Organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary, Meyers says. Cisco Talos warns that the organizations best equipped to handle the coming deluge of additional vulnerabilities, alerts, and incidents will be the ones that prepare now by deploying their own AI-assisted security capabilities. Security teams should assume AI is already embedded in attacker workflows, focus on detecting malicious behavior rather than proving AI involvement, treat large language models and APIs as privileged, high-risk infrastructure, and strengthen logging, patching, and containment, according to Oliver Simonnet, lead cybersecurity researcher at AI security and governance platform CultureAI. When censored models refuse to assist with malicious requests, threat actors simply switch to uncensored alternatives, making guardrails an insufficient defense on their own. Enterprises that delay integrating AI into their defensive operations risk falling permanently behind adversaries who have already made it central to their attack cycles, creating a widening capability gap that traditional security tools alone cannot close.