TLDRocket
Sign in

Agentic AI is compressing attacker intrusion timelines to minutes

SiliconANGLE Kristen Nicole Covered by 5 sources

Attackers are using AI agents inside real intrusions now. That’s cutting some break-ins down to minutes, which leaves defenders almost no runway.

Based on reporting by SiliconANGLE, Kristen Nicole — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

AI in cybercrime has moved well past the demo stage. CrowdStrike’s Adam Meyers says agentic adversaries are now showing up in extortion, espionage and hacktivist work, and the main change is speed. The tools are letting attackers do more, faster, rather than inventing some dazzling new trick.

Meyers told theCUBE at Fal.Con that CrowdStrike was tracking about 26 agentic adversaries in the last 30 days, more than it had tracked in the year before that. One example was REVENANT SPIDER, which he said was using an agent during the intrusion. In other words, AI agents are already inside ransomware operations, not circling them from a safe distance.

The timing is what should worry defenders. Meyers pointed to VAULT PANDA doing 1,100 commands in 58 minutes, with the agent learning as the team watched. He also said CrowdStrike’s global threat report had put average breakout time this year at 29 minutes, with the fastest at 27 seconds. That leaves very little room for the old playbook of notice, verify, contain, breathe.

And the argument here is not just that attacks are faster. It is that entire intrusion operations can now be completed in minutes from start to finish. CrowdStrike’s response has been collective action, including work with law enforcement on the Sality botnet disruption, which Meyers said had taken a decade and targeted a network that had been running for 23 years. His point was blunt: raise the cost for attackers, but do it responsibly.

My take — AI-written commentary, not fact-checked reporting

The loudest AI debate still gets stuck on model politics, while the real action is in crimeware that runs on whatever works. Open or closed matters less than whether defenders can keep up when an intrusion is over before the coffee cools. The industry keeps selling “transformation”; attackers just call it Tuesday.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.