All Incidents
CrowdStrike: Adversaries Hijacked AI Security Tools at 90+ Organizations in 2025. The Next Wave of AI Agents Has Write Access to the Firewall.
BreakingAPR 21, 2026SUPPLY CHAIN ATTACK

CrowdStrike: Adversaries Hijacked AI Security Tools at 90+ Organizations in 2025. The Next Wave of AI Agents Has Write Access to the Firewall.

CrowdStrike's 2026 Global Threat Report documents adversaries compromising AI tools at more than 90 organizations in 2025. The companies that were hit were using AI tools for security. The AI tools became the attack vector.

But the report flags something worse coming. The autonomous AI agents deploying now have more privilege than the ones that were compromised last year. They are not just reading data. They have write access. They can modify configurations, change firewall rules, alter security policies, and take irreversible actions, all without a human reviewing the output.

The Vercel breach last week followed exactly this pattern: a third-party AI tool used by one employee became the door into the entire platform. Now CrowdStrike is documenting that this happened at 90 organizations, and warning that the next generation of AI agents has even more dangerous access.

The tools that were supposed to protect you are the ones being used against you. And nobody put a human in the loop.

HOFFICIALHITL Score
HITL Score0/100
Why this matters to youNo jargon — just what it means

Think of the AI tools a company buys to guard its systems — digital security guards. Now imagine burglars figuring out how to turn those very guards against the building. That's what a major security firm documented: at more than 90 organizations, attackers got in by hijacking the AI tools meant to protect them. The shield became the way in.

Why it's a big deal: the report warns the next batch of these AI tools is even riskier. The older ones could mostly just read information. The new ones can change things — rewrite the locks, alter the rules, take actions that can't be undone — all without a person checking their work first. So if one gets hijacked, the damage isn't just snooping. It's sabotage.

So how does it touch you? The companies holding your money, your medical records, your personal details are leaning on these tools to keep the bad guys out — and the bad guys have learned to climb in through the guard. When the very thing built to protect you can be flipped into the weapon, the only real safeguard left is a human paying attention. Far too often, there isn't one.

🖤 Explained by Babycakes.
Read the full source →
Source: CROWDSTRIKE / VENTUREBEAT