Security

Nation-State Hackers With AI at Hand Exploit Vulnerabilities Within a Day of PoC Disclosure

IT DAILY ·

AI로 생성한 이미지

✦ AI Summary

CrowdStrike said in its release of the "2026 Threat Hunting Report" that AI is affecting the speed and methods of cyberattacks.

The report cited cases in which Chinese-linked threat actors achieved exploitation within 24 hours of PoC disclosure and cases in which software supply chain attacks resulted from poisoned development tools that exploited interest in AI.

A Fortinet report said the time to first attack after vulnerability disclosure, or TTE, has fallen to an average of 24 to 48 hours, and CrowdStrike said AI is being used both as an attack tool and as a target.

Artificial intelligence (AI) is changing the shape of modern cyberattacks, according to an industry announcement on the 20th. CrowdStrike said it released its "2026 Threat Hunting Report" that day, and the report was based on tracking information from more than 290 major threat actors compiled by CrowdStrike threat hunters and intelligence analysts.

The report examined nation-state hacking groups' use of AI and said AI is affecting the speed and methods of cyberattacks. In particular, it cited cases of Chinese-linked threat actors achieving exploitation within 24 hours of PoC disclosure, and said successful exploitation is taking place within 24 hours of vulnerability disclosure.

A PoC is source code that demonstrates the possibility of exploiting a vulnerability. The report said the original purpose of releasing PoCs is to help companies build defenses, but that they can also be misused, leading hackers to use them in attacks.

The report also covered cases in which development tools were poisoned by exploiting interest in AI. It said a method has emerged that contaminates development environments by using the AI boom as bait, and that this has in turn led to software supply chain attacks.

According to Tenable's analysis of the period from January 1, 2024, to September 30, 2025, there were 63,862 CVE vulnerabilities during that period, and 1,665 of them had PoC code disclosed, for a PoC disclosure rate of 2.6%. It also found that 56% of PoC-disclosed vulnerabilities saw PoCs appear within less than 7 days of the CVE becoming known. This shows that there was generally some time between CVE disclosure and the appearance of a PoC, and the article said that PoC-based exploitation also requires some time.

Fortinet's "2026 Global Threat Landscape Report" also said that this time has been shortening due to AI, and that the time to first attack after vulnerability disclosure, or TTE (Time-To-Explicit), was 24 to 48 hours on average. That is much shorter than last year's average TTE of 4.76 days, which was used as the comparison benchmark.

This shortening trend was also confirmed in the case of "React2Shell (React2Shell, CVE-2025-55182)," a vulnerability discovered in December last year. A PoC code appeared within hours of its disclosure, and CrowdStrike's threat hunting service "Overwatch" responded to more than 800 attacks related to more than 80 affected organizations four days after React2Shell was disclosed.

The security industry sees AI as a possible factor in the acceleration of attack speeds. The CrowdStrike report suggests that this change is spreading to nation-state hacker activity as well. Chinese-linked hacker groups are believed to be exploiting newly patched vulnerabilities within 2 days.

At the same time, nation-state hacking groups are targeting AI directly, beyond using it as an attack tool. The North Korea-linked hacker group STARDUST CHOLLIMA was found to have poisoned 131 malicious packages in the Mastra AI framework. In this trend, attacks that exploit interest in the AI ecosystem are continuing as well.

In particular, the popularity of "Vibe Coding" and the spread of automated "Vibe Coding" are fostering a culture of using unverified code. Hackers are also exploiting this habit of borrowing code without verification. They post malicious packages under names similar to well-known programs, compromise developer accounts, and hide malicious code inside legitimate libraries.

While nation-state hacking groups are focusing on specific targets, this case raised signs pointing to a North Korea-linked hacking group as the attacker, and a widely used software component was confirmed as the target. The target was the JavaScript package Axios, and in a separate case beyond this one, the Google Threat Intelligence Group also identified signs in April this year.

Adam Meyers said that AI is embedded in modern cyberattacks. He noted that as AI changes attack methods, the attack surface companies must defend is also expanding.

Adam Meyers stressed that companies need to be as proactive about AI protection as they are about AI adoption. He also argued that AI should be used for defense in ways that match attackers' speed.

Separately, React2Shell is a security vulnerability in React, a web framework widely used around the world. The CVE ID for the vulnerability is "CVE-2025-55182."

If React2Shell is exploited, unauthorized server-side code execution becomes possible. This illustrates the risks that can arise in React environments.

As shown in the article, nation-state and North Korea-linked hacker groups have targeted widely used software components, while AI is becoming deeply embedded in attacks, widening the scope of corporate defense. It also noted the need to expand AI adoption, protect AI itself, and use AI as a defense tool, while separately explaining the concept and risks of the React vulnerability React2Shell.

Python is widely used in AI development. Against this backdrop, Mastra is an open-source AI framework based on JavaScript that was released in 2024.

Based on its independence from the Python ecosystem, Mastra supports JavaScript developers in building AI agents and workflows.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241115

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.