CrowdStrike launches $100,000 AI security challenge with AWS

scanx
Reviewed by
Ritika DScanX News Team
Key Highlights

CrowdStrike and AWS launch 'AI Unlocked: Agents of Chaos', a $100,000 virtual AI security challenge starting August 31. The three-act competition tasks players with defending against prompt injection and agent hijacking, reflecting real-world enterprise risks. Prizes include $10,000 for Act 1, $20,000 for Act 2, and $70,000 for Act 3, concluding on September 29.

powered bylight_fuzz_icon
47488276

*this image is generated using AI for illustrative purposes only.

CrowdStrike (NASDAQ: CRWD) announced the launch of a $100,000 international AI security challenge in collaboration with Amazon Web Services (AWS) to address emerging risks in autonomous machine identities. Titled AI Unlocked: Agents of Chaos, the virtual red teaming game begins on August 31 and challenges participants to secure AI agents against manipulation techniques such as prompt injection. The initiative highlights a critical shift in enterprise security, where traditional defenses are insufficient for autonomous agents that execute code and access systems at machine speed.

The competition is structured across three distinct acts, each offering specific prize pools and running concurrently or sequentially through September 29. Players must navigate a fictional scenario involving a shadow organization weaponizing AI agents, requiring them to use adversarial techniques to stop malicious actions before their cover is blown. The stakes reflect CrowdStrike’s position as a pioneer in AI Detection and Response (AIDR), aiming to gamify the learning process for security defenders facing novel threats like agent hijacking and rogue AI behavior.

Competition Structure and Prizes

The $100,000 total prize pool is distributed across three acts, with pre-registration open globally. An on-site gameplay experience will also be available at Fal.Con 2026. The schedule and rewards are detailed below:

Act Name Duration Prize Pool
Act 1: The Sanctum August 31 to September 7 $10,000
Act 2: The Gatekeeper August 31 to September 14 $20,000
Act 3: The Basilisk September 15 to September 29 $70,000

Players earn points for solving puzzles while managing token consumption, with the highest score at the close of each act winning the respective prize. Participants can replay puzzles to refine their approach, simulating the iterative nature of real-world security defense.

Strategic Context

Jennifer Johnson, chief marketing officer at CrowdStrike, stated that prompt injection and agent hijacking are no longer theoretical risks, noting that agents are already breaking containment in enterprise environments. She described the challenge as an interactive way to give defenders hands-on experience with these novel threats. As organizations deploy AI rapidly, every agent becomes a new identity to govern and a new attack surface to defend, necessitating specialized tools like CrowdStrike’s Falcon AIDR platform.

The challenge underscores the limitations of traditional security architectures, which were not built to secure autonomous machine identities that move data with real credentials. By providing a live gaming environment, CrowdStrike aims to educate the security community on how agents can be manipulated and why runtime security is essential. The event runs from August 31 at 12:00 PM PT to September 29 at 11:59 PM PT, open to participants of majority age in their jurisdiction.

How might the techniques revealed in this challenge influence the evolution of CrowdStrike's Falcon AIDR platform and its pricing strategy for enterprise clients?

What regulatory implications could arise if autonomous AI agents begin routinely bypassing traditional security controls as demonstrated in this simulation?

Could this gamified approach to security training become a standard industry practice, potentially disrupting traditional cybersecurity certification markets?

like19
dislike

CrowdStrike finds AI embedded in adversary operations, exploitation windows collapse

scanx
Reviewed by
Ritika DScanX News Team
Key Highlights

CrowdStrike’s 2026 Threat Hunting Report reveals AI is now central to adversary operations, with exploitation windows shrinking to under 48 hours for most vulnerabilities. China-nexus actors like VAULT PANDA attacked within 24 hours of disclosure, while cloud eCrime surged 171%. DPRK-linked STARDUST CHOLLIMA poisoned 131 AI framework packages, highlighting the growing risk to AI supply chains.

powered bylight_fuzz_icon
47286573

*this image is generated using AI for illustrative purposes only.

CrowdStrike (NASDAQ: CRWD) released its 2026 Threat Hunting Report on Aug 3, 2026, revealing that artificial intelligence has become deeply embedded in modern adversary operations. The report indicates that threat actors are now using AI as both a tool and a target, significantly accelerating the speed and scale of cyberattacks. For enterprises, this shift means exploitation windows have collapsed from days to hours, forcing security teams to defend against AI-driven threats that move faster than traditional human-led campaigns. This operational reality underscores an urgent need for organizations to secure their AI infrastructure as aggressively as they adopt it.

The findings are based on frontline intelligence from CrowdStrike’s elite threat hunters and intelligence analysts, who track more than 290 named adversaries. Adam Meyers, head of counter adversary operations at CrowdStrike, stated that AI is changing how attacks are planned, executed, and scaled. He noted that the organizations that succeed will be those that use AI to defend at the speed of the adversary.

Key Findings from the 2026 Threat Hunting Report

The report outlines several critical trends in adversary behavior during the first half of 2026:

Metric Value Context
Exploitation Window Within 48 hours 88% of observed exploitations occurred within this timeframe after PoC release
China-Nexus Speed Within 24 hours VAULT PANDA and GENESIS PANDA launched attacks within this window
Cloud eCrime Surge 171% increase Driven by credential theft, cryptomining, and LLM abuse
Vishing Intrusions 2x increase Observed in 1H 2026
Device Code Phishing 15x increase Monthly attempts rose sharply in 1H 2026

Supply Chain and AI Infrastructure Targets

The AI ecosystem has emerged as the next supply chain battleground. DPRK-nexus adversary STARDUST CHOLLIMA injected malicious code into 131 trusted Mastra AI framework packages via npm. During the first half of 2026, 87% of identified software registry threats involved malicious npm packages. Meanwhile, eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.

Adversaries are also following AI workloads into the cloud. Cloud-conscious eCrime activity surged by 171%, with actors executing credential theft, cryptomining, large language model (LLM) abuse, and digital financial asset theft. In one notable campaign, adversaries sent nearly 200,000 AI model requests in just two minutes, demonstrating the scale at which AI infrastructure can be abused.

Authentication and Detection Dynamics

Trusted authentication mechanisms are increasingly becoming attack paths. Vishing intrusions doubled in the first half of 2026. ECrime groups CORDIAL SPIDER and SNARKY SPIDER compromised single sign-on (SSO) integrated SaaS applications for data exfiltration. In one incident, SNARKY SPIDER moved from account takeover to data theft in under five minutes. Monthly device code phishing attempts increased by 15x in 1H 2026, reflecting the growing abuse of trusted authentication workflows.

On the defense side, CrowdStrike OverWatch observed that AI agent-triggered detection leads grew at 2.5x the rate of human-triggered leads. This acceleration highlights how AI is increasing the volume and velocity of activity that security teams must investigate, necessitating automated protection and remediation capabilities.

What the Numbers Show

The convergence of AI adoption and adversary capability is compressing the time available for response. With 88% of vulnerabilities being exploited within 48 hours of proof-of-concept release, and specific state-aligned actors like VAULT PANDA moving within 24 hours, traditional patching cycles are no longer sufficient. The data suggests that the primary risk is no longer just the existence of a vulnerability, but the speed at which AI-enabled adversaries can weaponize it. Furthermore, the 15x increase in device code phishing attempts indicates that attackers are systematically bypassing traditional multi-factor authentication by exploiting trusted user workflows, shifting the burden of defense onto behavioral detection rather than static credentials.

How will the 48-hour exploitation window force enterprises to restructure their patch management and zero-trust architectures?

What regulatory or industry standards might emerge to govern the security auditing of AI frameworks like Mastra following the npm supply chain attacks?

Which cybersecurity vendors are best positioned to provide automated, AI-driven defense capabilities that can match the velocity of adversary attacks?

like19
dislike

More News on CrowdStrike Holdings Inc