CrowdStrike、AI がサイバー兵器かつ標的と警告
本文の状態
日本語全文を表示中
詳細モードで約9分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
ZDNET AI
CrowdStrike の調査によると、AI は攻撃の武器であると同時に防御が困難な標的となり、既存のセキュリティ戦略の見直しが迫られている。
AI深層分析を開く2026年8月4日 15:53
AI深層分析
キーポイント
AI の二重性:武器と標的
ビジネスに成長をもたらす AI モデルやツールが、サイバー犯罪者によって攻撃兵器として悪用される一方で、それ自体が新たな脆弱性を抱えた標的となっている。
LLMJacking による大規模攻撃
2 分間に約 20 万回の API 呼び出しを行う「LLMJacking」と呼ばれる攻撃手法が確認され、AI を利用した攻撃のスピードと規模が拡大している。
防御の限界と攻撃速度の乖離
悪意ある AI がセキュリティ上の欠陥を発見・悪用する速度が、セキュリティ担当者がパッチを適用して修復する速度を上回っている状況にある。
無防備な攻撃面の拡大
エンドポイントデバイスの増加や大規模言語モデル(LLM)の導入に伴い、組織が意図せずデータ窃取や計算資源の不正利用を許す「無防備な」領域を広げている。
AI による攻撃信号の増加と検知の困難化
AI エージェントが引き起こす脅威候補は手動駆動型よりも2.5倍に増え、防御側が悪意のある活動と期待される AI 動作を区別することが難しくなっている。
重要な引用
AI is not just the tool or weapon that is being used
forcing businesses to rethink their defensive strategies in light of attack signals far outstripping what cybersecurity experts can manually handle
LLMJacking made nearly 200,000 API calls in two minutes
"We're seeing threat actors really adopt AI at the same speed that everybody else is."
編集コメントを表示
編集コメント
2026 年の脅威ハンティングレポートに基づき、AI のセキュリティリスクが実害として顕在化していることが示唆される。攻撃の自動化と速度が人間の対応能力を凌駕する現状は、単なる技術的な課題を超えた経営上の危機管理事項へと昇格している。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

*ZDNET のフォロー: *Google で優先ソースとして追加* してください。*
ZDNET の注目ポイント
- クラウドストライクは、AI が攻撃対象であると同時に兵器にもなりうると警告している。
- LLMJacking(大規模言語モデル乗っ取り)により、わずか2分間で約20万件のAPI呼び出しが行われた。
- 悪意のあるAI は、防御側が脆弱性を修正するよりも速く欠陥を悪用し始めている。
研究者たちは、人工知能(AI)がますます「敵対的なツールであり、同時に攻撃目標でもある」と指摘しています。これにより、サイバーセキュリティの専門家が手作業で処理できる範囲をはるかに上回る攻撃シグナルに対応するため、企業は防御戦略の見直しを迫られています。
クラウドストライクが月曜日に発表した『2026 脅威ハンティングレポート』によると、ビジネスに成長と生産性の機会をもたらす同じ AI モデル、ツール、ワークフローが、サイバー犯罪者によって次々と兵器化されています。
関連記事: Google は AI エージェントを使って、わずか60日間で1,072件の Chrome のセキュリティバグを発見・修正した
企業のネットワークが拡大し、エンドポイントデバイスが増加し、さまざまなワークロードを処理するために新しい大規模言語モデル(LLM)が導入されるにつれ、組織は意図せずしてデータ窃取や AI モデルへのアクセス取得、監視、さらには計算資源の奪取に悪用される「防御されていない」攻撃対象領域を拡大させています。
AI:新たな武器であり標的
CrowdStrike の脅威インテリジェンス担当責任者であるアダム・マイヤーズ氏は、「AI は単なる使用されるツールや兵器ではなく、それ自体が攻撃対象領域となっている」と指摘しています。「脅威アクターも、他の人々と同様に AI を急速に採用しているのが見えています。」
CrowdStrike のレポートによると、人工知能(その多くは新しくて未検証のもの)の広範な導入により、防御側が処理すべきシグナルの量が劇的に増加しています。
関連記事: AI によるサイバー攻撃は未来である:企業の 43% がすでに被害に遭っている
現在、同社の脅威ハンターが調査する必要がある AI エージェントによってトリガーされたリードは、手動で処理されるリードの 2.5 倍に達しており、CrowdStrike はこれが「防御側にとって、悪意のある活動と予想される AI に基づく行動を区別することをより困難にしている」と述べています。
不審なアラートやシグナルは、犯罪世界における AI を活用した活動と、攻撃が現在行われている驚異的な速度を浮き彫りにしています。CrowdStrike はその具体例として以下のような事例を挙げています:
有名なチョリマ: 北朝鮮(DPRK)に関連するグループは、仮想通貨やブロックチェーン関連企業への侵入を試みるため、信頼できる AI 環境やツールを積極的に武器化しています。AI が生成した履歴書からディープフェイクによる面接まで、あらゆる手口を用いています。
コルディア・スパイダーとスナッキー・スパイダー: これらのグループは「ヴィッシング(音声フィッシング)」を活用し、SaaS アプリからデータを窃取したり、シングルサインオンアカウントを乗っ取ったりします。研究者が記録したある事例では、アカウントの乗っ取りからデータ窃盗へと移行するまでに 5 分未満しかかかりませんでした。
LLMJacking: LLMJacking とは、脅威アクターが企業の AI モデルにアクセスするための鍵や認証情報を入手してしまう事象です。クラウドベースであることが一般的なこれらの大規模言語モデル(LLM)へのアクセス権を握った脅威アクターは、データの窃取や、悪意のあるタスクの実行、あるいは膨大な計算リソースを要する処理の強制など、甚大な被害をもたらすことができます。これにより、被害企業には巨額の請求書が突きつけられることになります。例えば CrowdStrike によると、あるキャンペーンでは被害企業の LLM が 2 分間に約 20 万件の API リクエストを実行し、「大規模な財務および運営への影響」を引き起こしました。
現在、サイバー犯罪者が生成するフィッシングや電話詐欺(ヴィッシング)の素材、マルウェアのパイロード、攻撃コマンドの多くは AI によって作成されています。これにより攻撃チェーンが効率化され、初期アクセスを狙ったより説得力のあるフィッシングスキームも生み出される可能性があります。マイヤーズ氏は、これらの生成物はますます個別最適化されており、AI や大規模言語モデル(LLM)を用いて異なる防御シナリオに対応するカスタムツールが開発されていると指摘しています。
脆弱性対策のタイムリミット消失:防御者にとってさらに厳しい状況
レポートで強調されたもう一つの懸念すべき傾向は、脆弱性の発見から悪用までの間に、人間による防御者やその支援ツールが対応できる時間が急速に縮まっているという点です。
2026 年 1 月から 6 月の期間中、CrowdStrike が検知した攻撃の 88% は、公開された概念実証(PoC)コードのリリースから 48 時間以内に実行されました。
関連記事: OpenAI だけでなく Anthropic も「Claude のハッキング行為は理想とは程遠い」と指摘
中国の Vault Panda や Genesis Panda といった脅威グループの中には、新たな脆弱性をより厳密に監視しているところもあります。彼らは、ある Web アプリケーション(React2Shell)における深刻な欠陥について、公開からわずか 1 日以内に実際の悪用コードを開発しました。
このように、AI は両刃の剣として機能します。最近公開された 3 つのローカル権限昇格(LPE)エクスプロイトのうち、2 つである「CopyFail」と「Fragnesia」(3 つ目は「Dirty Frag」)は、AI を活用した調査によって発見されました。報告書には、「脅威アクターはこれらの脆弱性を即座に実運用に取り入れた」と記されています。
これは企業とそのセキュリティチームにとって何を意味するのでしょうか。CrowdStrike によると、対応時間はますます短縮されることになります。その背景には、AI の兵器化が一部で寄与していることは間違いありません。
関連記事: Claude AI が共有したチャットが Google にインデックスされている - あなたの会話も公開されたか確認
「この傾向は最先端 AI モデルの登場以前から存在していましたが、これらのシステムの導入により、脆弱性の発見とエクスプロイト開発が加速することで、脆弱性悪用のタイムラインが圧縮される可能性があります。その結果、すでに追いつくのに苦労している防御側への圧力が高まる恐れがあります」と研究者は述べています。
対策を講じる
AI は盾として機能することもありますが、CrowdStrike の研究が示すように、武器としても利用され得ます。
関連記事: オープンウェイトとクローズド:AI を巡る内戦が始まろうとしている、その賭けは存亡に関わる
AI に起因する圧力により、防御側が責任を持つネットワークやエンドポイントの制御を維持し、セキュリティを確保するのは極めて困難になります。そのため、チームは企業が以下の対策を採用することを推奨しています:
AI はサイバー兵器であると同時に、巨大な標的でもあります。CrowdStrike が警告を発しています。
AI アプリケーションと大規模言語モデル(LLM)の保護: AI は現在、複数のビジネス環境に組み込まれています。企業は最小権限の原則を適用し、AI 関連の認証情報を保護するとともに、不審な LLM の利用やコストの急増を検知して監視することで、新たな事業リスクと運用リスクを低減させるべきです。
アイデンティティが主要な攻撃対象領域となる: この問題は AI が登場する以前から存在しましたが、今ではセキュリティ確保と アイデンティティの検証 の重要性はさらに高まっています。組織はフィッシング耐性のある多要素認証を義務付け、企業リソースへのアクセスを監視し、人間および非人間のアカウントに対して最小権限の原則を適用すべきです。
ドメイン間の見落としやソフトウェアサプライチェーンのセキュリティ対策: サプライチェーン内や自社のネットワーク内にデジタルな盲点があると、そこが攻撃に悪用される恐れがあります。テレメトリ(運用データ)、行動検知・分析ソフトウェア、頻繁なパッチ適用サイクル、そして脅威インテリジェンスを活用することで、侵害リスクを低減できます。
積極的な対応へ: AI を兵器として利用する動きは、我々が追いつくことのできないスピードで進行しており、組織に受動的から能動的なセキュリティ姿勢への転換を迫っています。投資、脅威の優先順位付け、そして現在のネットワークを脅かすレガシー(既存)セキュリティ課題への対応は、すべて迅速に行う必要があります。攻撃対象領域を減らすことで、チームが追いつくための猶予時間を確保できるのです。
原文を表示

*Follow ZDNET: *Add us as a preferred source* on Google.*
ZDNET's key takeaways
- CrowdStrike warns AI is both a target and a weapon.
- LLMJacking made nearly 200,000 API calls in two minutes.
- Malicious AI exploits flaws faster than defenders can patch them.
Artificial intelligence is increasingly "an adversary tool and target," researchers said, forcing businesses to rethink their defensive strategies in light of attack signals far outstripping what cybersecurity experts can manually handle. **
**
According to CrowdStrike's 2026 Threat Hunting Report, published on Monday, the same AI models, tools, and workflows that are giving businesses growth and productivity opportunities are being weaponized by cybercriminals in droves.
Also: How Google used AI agents to find and fix 1,072 Chrome security bugs - in 60 days
As corporate networks expand, endpoint devices are added, and new large language models (LLMs) are deployed to handle various workloads, organizations are also unwittingly creating larger "undefended" attack surfaces that can be exploited to steal data, obtain AI model access, conduct surveillance, and potentially even harvest computing power for their own ends.
AI: The new weapon and target
"AI is not just the tool or weapon that is being used, but it is also the attack surface," Adam Meyers, head of threat intel at CrowdStrike, commented. "We're seeing threat actors really adopt AI at the same speed that everybody else is."
CrowdStrike's report said that the widespread adoption of artificial intelligence (much of it new and unproven) is increasing the sheer volume of signals that defenders have to sort through.
Also: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
There are now 2.5 times as many AI agent-triggered leads for the firm's threat hunters to examine as there are manually driven leads, which CrowdStrike said "makes it more difficult for defenders to distinguish malicious activity from expected AI-driven behavior."
Suspicious alerts and signals underscore AI-driven activity in the criminal world -- and the rapid speeds at which attacks are now being conducted. CrowdStrike gave a number of examples, including:
- Famous Chollima: A Democratic People's Republic of Korea (DPRK)-associated group is actively weaponizing trusted AI environments and tools to try to gain entry to companies working in cryptocurrency and the blockchain, using everything from AI-generated resumes to deepfake interviews.
- Cordial Spider, Snarky Spider: These groups use vishing to exfiltrate data from SaaS apps and compromise single sign-on accounts. In one case documented by the researchers, an attack shifted from account takeover to data theft in less than five minutes.
- LLMJacking: LLMJacking occurs when a threat actor gains access to keys or credentials used to access a company's AI models. Armed with access to these LLMs -- which are typically cloud-based -- threat actors can then steal data and wreak havoc, such as forcing the model to perform malicious tasks or those that demand high compute power, creating massive bills for the victim. For example, CrowdStrike said that in one campaign, the victim's LLM was used to generate close to 200,000 API requests in two minutes, "resulting in large-scale financial and operational impact."
AI is mostly used by cybercriminals today to generate phishing and vishing material, payloads, and commands, streamlining their attack chains and potentially creating more convincing phishing schemes designed for initial access. Meyers said these creations are becoming more bespoke, with custom tools generated by AI and LLMs to manage different defense scenarios.
Vulnerability windows vanish: More bad news for defenders
Another concerning trend highlighted in the report is the shrinking window that human defenders -- and their tools -- have to respond between vulnerability discovery and exploitation.
From January through June 2026, 88% of exploits detected by CrowdStrike were launched within 48 hours of a public proof-of-concept (PoC) code release.
Also: Not just OpenAI - Anthropic says Claude's hacking spree 'falls short of ideal behavior'
Some threat groups, such as China's Vault Panda and Genesis Panda, are keeping an even closer eye on new bugs: They developed working exploits for a critical vulnerability in a web application (React2Shell) within a day of disclosure.
In these situations, AI goes both ways. Two out of three recently disclosed LPE exploits, CopyFail and Fragnesia (Dirty Frag being the third), were discovered by AI-assisted research, and the report said "threat actors wasted no time incorporating them into active operations."
What does this mean for the enterprise and its cybersecurity teams? According to CrowdStrike, response times are going to become shorter and shorter -- no doubt due in part to the weaponization of AI.
Also: Claude AI shared chats indexed by Google - see if your conversations were exposed
"While this pattern predates the emergence of frontier AI models, the implementation of these systems is likely to compress vulnerability exploitation timelines by accelerating vulnerability discovery and exploit development," the researchers said. "This could, in turn, increase the pressure on defenders already struggling to keep pace."
Your move
AI can act as a shield, but as CrowdStrike's research revealed, it can also be a weapon.
Also: Open weights vs. closed: An AI civil war's afoot, and the stakes are existential
With the pressure caused by AI, defenders will be hard-pressed to retain control and secure the networks and endpoints they are responsible for, and so the team recommended that businesses adopt the following practices:
- Secure your AI applications and LLMs: With AI now embedded across multiple business environments, companies should enforce least-privilege principles, protect AI-related credentials, and monitor for suspicious LLM usage or cost spikes to reduce emerging business and operational risk.
- Identity is a primary attack surface: This issue existed before AI, but now, securing and verifying identities is even more important. Organizations should enforce phishing-resistant multifactor authentication, monitor access to corporate resources, and apply least privilege to human and non-human accounts.
- Tackle cross-domain blind spots and secure the software supply chain: Digital blind spots in the supply chain and in your own networks can be exploited. Telemetry, behavioral detection and analysis software, frequent patch cycles, and threat intelligence can reduce the risk of compromise.
- Be proactive: AI weaponization, moving at a speed we can't, is now forcing organizations to shift from a reactive to a proactive security stance. Investment, threat triage, and tackling the legacy security issues that threaten today's networks should all be handled quickly. By reducing the attack surface, you'll give your teams the breathing space to keep up.
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み