Artificial intelligence has become one of the most powerful tools in modern cybersecurity, helping organizations detect threats, automate investigations, and strengthen defensive operations. Yet as AI systems become more deeply integrated into enterprise infrastructure, security researchers are increasingly warning that the technology itself is becoming a primary attack target. New research from CrowdStrike suggests that cybercriminals are no longer treating AI merely as a tool to abuse—they are beginning to treat AI systems as infrastructure that can be compromised, manipulated, and exploited.
According to CrowdStrike’s latest findings, attackers are rapidly expanding their focus beyond traditional endpoints and cloud workloads toward AI-powered applications, autonomous agents, and machine learning infrastructure. At the same time, the company observes that Microsoft’s continued efforts to reduce the Windows kernel attack surface are forcing adversaries to rethink long-established techniques, accelerating a broader shift toward identity attacks, cloud compromise, and AI-focused exploitation.
The report reflects an important evolution in the cyber threat landscape.
For decades, endpoint exploitation largely revolved around operating system vulnerabilities, privilege escalation flaws, kernel-level malware, and techniques designed to bypass traditional security software. Windows, as the dominant enterprise operating system, naturally became the preferred target for sophisticated attackers seeking deep system access.
However, Microsoft’s sustained investment in platform security—including virtualization-based security, kernel hardening, memory protections, driver signing requirements, hardware-backed isolation, and improvements introduced through the Secure Future Initiative—has steadily reduced the opportunities available to attackers operating at the kernel level.
While Windows remains a frequent target, successfully compromising the operating system has become considerably more difficult than in previous years.
CrowdStrike argues that attackers are responding by redirecting their efforts toward areas where security maturity is lower and potential rewards remain high.
Artificial intelligence represents one of those emerging frontiers.
Modern AI deployments involve far more than language models. Enterprise AI ecosystems now include inference servers, vector databases, orchestration frameworks, retrieval pipelines, autonomous agents, prompt management systems, model repositories, API gateways, cloud storage, and privileged integrations with business applications. Every component introduces additional attack surfaces that did not exist in traditional enterprise architectures.
Rather than attacking the underlying operating system, adversaries increasingly seek to manipulate the AI itself.
Prompt injection remains one of the most visible examples. By embedding carefully crafted instructions inside emails, documents, websites, or external data sources, attackers attempt to influence how AI assistants interpret information and make decisions. In autonomous systems capable of executing workflows, these manipulations may cause AI agents to reveal sensitive information, ignore security policies, perform unintended actions, or interact with unauthorized external resources.
Researchers have also demonstrated attacks involving model poisoning, retrieval manipulation, malicious training datasets, insecure plugins, exposed AI APIs, compromised model repositories, and adversarial inputs designed to bypass safety mechanisms.
Unlike conventional software vulnerabilities, many of these attacks target the reasoning process rather than the underlying code.
This distinction significantly changes enterprise security priorities.
Traditional cybersecurity focused heavily on preventing unauthorized code execution. AI security increasingly centers on protecting decision-making itself. Organizations must ensure not only that systems execute correctly, but also that AI agents receive trustworthy information, maintain appropriate context, resist manipulation, and operate within carefully defined authorization boundaries.
CrowdStrike’s observations suggest that attackers are already adapting to this reality.
As Windows becomes progressively harder to exploit through conventional kernel-level techniques, cybercriminals appear to be pursuing identity compromise, cloud account hijacking, software supply chain attacks, and AI workflow manipulation where the defensive landscape remains comparatively immature.
Identity has become particularly important.
Many AI systems operate using privileged service accounts capable of accessing cloud resources, repositories, customer databases, collaboration platforms, and internal knowledge bases. Compromising those identities may provide attackers with significantly greater operational value than exploiting an individual workstation.
Similarly, autonomous AI agents increasingly execute tasks traditionally reserved for human administrators. They interact with APIs, modify source code, generate infrastructure configurations, process confidential documents, and automate operational workflows. Each permission granted to these agents effectively expands the organization’s identity attack surface.
The report also reinforces a broader industry trend toward zero-trust security for artificial intelligence.
Rather than assuming AI systems can safely consume any available information, organizations are implementing stricter controls around data provenance, model integrity, permission management, runtime monitoring, and behavioral analysis. AI agents are increasingly treated as non-human identities subject to continuous authentication, authorization, and auditing.
The changing threat landscape is also influencing defensive technologies.
Security platforms are evolving beyond endpoint detection and response to include specialized protections for AI workloads, model behavior analysis, prompt inspection, inference monitoring, API security, and continuous validation of AI-generated actions. These capabilities aim to identify abnormal model behavior before manipulated outputs lead to broader compromise.
CrowdStrike’s research ultimately highlights a fundamental shift in cybersecurity.
The industry’s most valuable assets are no longer limited to servers, endpoints, or cloud workloads. AI systems themselves are becoming critical infrastructure, processing sensitive information, making operational decisions, and interacting directly with enterprise resources. As their influence expands, they inevitably become attractive targets for increasingly sophisticated adversaries.
Meanwhile, Microsoft’s continued reduction of the Windows kernel attack surface demonstrates that sustained investment in platform security can successfully force attackers to evolve. Yet rather than disappearing, those adversaries simply redirect their attention toward newer technologies where security practices have not yet reached the same level of maturity.
The next phase of cybersecurity will therefore require organizations to defend two rapidly converging fronts simultaneously: increasingly hardened traditional operating systems and increasingly capable artificial intelligence platforms. Success will depend not only on securing code and infrastructure, but also on protecting the reasoning processes, identities, and autonomous workflows that now define the modern enterprise.