CrowdStrike and CoreWeave Train AI to Attack and Defend

CrowdStrike and CoreWeave Train AI to Attack and Defend

Twenty-seven seconds. That was the fastest eCrime breakout time CrowdStrike observed in 2025, meaning the time an attacker needed to move beyond the first foothold in a network. Bartley Richardson, chief of AI at CrowdStrike Holdings Inc., uses that number to argue that human analysts can no longer keep up without help. The help he has in mind is AI models trained on serious compute, and part of that compute comes from CoreWeave Inc.

Richardson and Jim Higgins, CoreWeave's chief information security officer, described the arrangement in a conversation with theCUBE Research's Dave Vellante and John Furrier at the Fully Connected event. TheCUBE is the livestreaming studio of SiliconANGLE Media. The talk covered three themes: defense at machine speed, security built into infrastructure, and trust in automated systems.

Why compute matters for defense

Richardson's case is simple. If attackers break out in seconds, the response has to be automated, and automated defense needs capacity for both training models and running them.

"You can't have humans combat this alone," he said. "You need machine-speed defense, and that relies on critical infrastructure."

That is where CoreWeave comes in. According to CrowdStrike, the cloud provider supplies training and inference capacity for SafeMind. CoreWeave also acts as a design partner for CrowdStrike's Cyber Superintelligence Lab. CrowdStrike contributes the security data and its knowledge of adversaries. CoreWeave contributes the infrastructure.

Attack models as a training source

The more interesting part is how the models learn. Richardson calls it "adversarial co-evolution." In practice, CrowdStrike builds offensive models whose job is to get around defensive operations. The defensive models are then trained on the results.

"We train and we steer the best offensive capabilities to attack, to find ways around defensive operations," Richardson said. "But then, we train these defensive models on large-scale infrastructure to learn from those attacks."

Put another way, every successful attack becomes training data. The approach sits in the same space as other recent work on defensive cyber AI, where vendors try to stay ahead of models that are getting better at offense.

Security without stopping the machine

CoreWeave has its own problem to solve. Its production systems cannot go offline for security work, so protection has to happen while everything keeps running. Higgins has a name for this.

"That's what I refer to as the aikido of the security problem," he said. Anything that improves security "while the machine is running and use its own energy to promote the security needs is exactly what I do."

For CoreWeave, that means using AI to scan code. It also means placing automation inside the continuous integration and continuous delivery (CI/CD) pipeline, the process that tests and ships software changes, so misconfigurations get fixed there before they reach production.

The basics still win

Higgins was careful not to oversell the AI angle. Attackers, he noted, work with limited budgets and limited time. They look for the cheapest way in, and several small, ordinary weaknesses combined can give them exactly that.

"When you say something is secure, test it and test it often to be sure, but also do the basics," he said. "Patch your stuff and continually test and monitor for those issues."

Trust as the finish line

CrowdStrike is investing in automation for always-on security operations. Richardson said those tools have to earn the confidence of CoreWeave and of CoreWeave's customers. He offered a definition of AI that frames the whole effort.

"People ask, 'When do we get to the end of AI?' And I say, 'Never,'" he said. "It's AI until you trust it. Then you start to think of it as automation."

For CrowdStrike, the priority as it builds AI that never switches off is "how trust is built into the system."

A disclosure from the original coverage: theCUBE is a paid media partner for Fully Connected, and CoreWeave sponsored theCUBE's coverage. SiliconANGLE states that sponsors have no editorial control.

Our Take

The partnership itself is a familiar shape: a security vendor brings data, a GPU cloud brings capacity. What stands out is the training method. Pitting offensive models against defensive ones is a reasonable answer to a real trend. Open models are getting closer to frontier systems at exploit building, and defenders need models that have actually seen those attacks. Whether this approach holds up outside the lab is the open question.

Two caveats are worth keeping in mind. First, the interview offers no numbers on how well SafeMind or the defensive models perform. The 27-second figure explains the urgency, not the results. Second, this came from a sponsored broadcast, so it is closer to a pitch than to an independent evaluation.

Higgins' comments may be the most useful part for most readers. His point that attackers chain together ordinary weaknesses fits a pattern seen in recent incidents, including AI agents leaking company screenshots through plain configuration mistakes. Fancy models do not replace patching.

What to watch next: whether CrowdStrike publishes measurable results from its Cyber Superintelligence Lab, and how it explains the guardrails on its own offensive models. Richardson's "AI until you trust it" line also sets a test. Trust will likely depend on transparency about failures, not just successes.