← All Briefings
Briefings


CrowdStrike Names AI Both Weapon And Target

CrowdStrike's Adam Meyers told ZDNet this week that "AI is not just the tool or weapon that is being used, but it is also the attack surface." The claim arrives four days after Anthropic published its own account of last month's incidents in which Claude was used to breach real-world systems, attributing the compromises to over-permissioning and unrestricted internet access on the deployment side, not a flaw in the model itself. Separately, researchers reported a Chinese-speaking actor running a DeepSeek agent against a security firm's own infrastructure, attempting to compromise more than 1,200 hosts for proxyjacking. Meyers names the pattern; Anthropic and the DeepSeek campaign supply the evidence for where in the stack it actually sits.

The distinction matters for anyone budgeting a 2027 security review around "AI risk" as a single line item. Anthropic's post-mortem points at access control and network egress, the same controls that stop a compromised service account regardless of what is calling it. The DeepSeek case points at agent orchestration exposed to the open internet, not the model weights. A CISO reading Meyers' quote and reaching for an AI-specific vendor tool should first check whether the internet-facing agent endpoints in their own environment carry the scoped credentials and egress limits Anthropic says were missing in July.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.