The CrowdStrike 2026 Threat Hunting Report highlights a new evolution in the tactics of cyber adversaries, who are increasingly exploiting the trust placed in users and legitimate tools. These malicious actors target identity systems, cloud environments, SaaS applications, AI services, software supply chains, and developer workflows to blend into legitimate business activities and reach critical assets before defenders can detect them.

The report underscores how LLMJacking campaigns have generated nearly 200,000 API requests in two minutes, causing widespread financial and operational impact. Additionally, vishing intrusions have doubled in the first half of 2026 compared to the second half of 2025. Groups like CORDIAL SPIDER and SNARKY SPIDER have used vishing to steal data from SaaS applications and compromise single sign-on accounts, with SNARKY SPIDER able to move from account takeover to data theft in less than five minutes.

Another alarming figure concerns phishing attempts for monthly device codes, which have increased by 15 times in the last six months. These numbers demonstrate how adversaries are rapidly adapting their tactics to exploit vulnerabilities and trust in modern technologies.

AI as a Tool and Target for Adversaries

The same AI technologies that are revolutionizing the business world are creating new underdefended attack surfaces that cyber adversaries do not hesitate to exploit. AI systems have become targets for malicious actors seeking to steal secrets, abuse AI model access, and exploit computing power.

Among these, the group FAMOUS CHOLLIMA, associated with the Democratic People's Republic of Korea (DPRK), stands out, having used AI-centered environments to compromise cryptocurrency and blockchain companies. FAMOUS CHOLLIMA's campaign was one of the most sophisticated examples of the AI Supply Chain Compromise (AML.T0010) initial access technique in the MITRE ATLAS™ framework.

The widespread adoption of AI is increasing the volume of signals that threat hunters must evaluate. According to CrowdStrike OverWatch, threat reports generated by AI agents are 2.5 times higher than those generated by manual activity, making it harder for defenders to distinguish between malicious activity and legitimate AI-driven behaviors.

Vulnerability Exploitation Windows Shrink to Hours

Adversaries are accelerating vulnerability exploitation, putting patching cycles under pressure. From January to June 2026, 88% of vulnerability exploitations with a public proof of concept (PoC) observed by CrowdStrike occurred within 48 hours of the PoC publication.

Groups connected to China, such as VAULT PANDA and GENESIS PANDA, launched deliberate attacks within 24 hours of the public disclosure of a critical vulnerability in web applications. After the disclosure of the React2Shell vulnerability, CrowdStrike OverWatch responded to over 800 hunting leads in just four days, affecting more than 80 victims.

The group connected to Belarus, UMBRAL BISON, also demonstrated rapid action, exploiting the Linux LPE CVE-2026-31431 vulnerability in April 2026. The day after the public disclosure of the vulnerability, a sector researcher released a PoC exploit and technical details. The next day, CrowdStrike OverWatch detected widespread dissemination of the exploit, with approximately 94% of the events in the first 24 hours related to testing behaviors based on the public PoC code. The activity connected to Belarus was discovered in just over 20 hours after the public disclosure.

CrowdStrike predicts that vulnerability exploitation times will continue to shrink. Although this pattern predates the emergence of frontier AI models, the implementation of these systems is likely to further compress exploitation times, accelerating vulnerability discovery and exploit development. This, in turn, will increase pressure on already struggling defenders to keep up.

Software Supply Chain Attacks Evolve

Adversaries are exploiting trust in the developer ecosystem as open-source dependency adoption accelerates. They are moving toward CI/CD pipelines, container registries, package registries, and integrated development environment (IDE) extensions, where a compromised dependency or trusted component can quickly spread to downstream environments.

In the past year, DPRK-connected groups like STARDUST CHOLLIMA and ALTERED SPIDER have led some of the most consequential software supply chain attacks, demonstrating how both state-affiliated and financially motivated actors are targeting this attack surface. ALTERED SPIDER, for example, compromised more than 300 software dependencies in a single day, collected credentials, and moved into cloud environments.

In March 2026, STARDUST CHOLLIMA used stolen maintainer credentials to compromise the Axios Node Package Manager (npm) package and deliver platform-specific variants of their ZshBucket malware. In June 2026, the same adversary injected a malicious npm package as a dependency in at least 131 Mastra AI framework packages, indicating that trusted AI building blocks are becoming supply chain targets.

The npm ecosystem, cited in the scenario above, is particularly vulnerable. Often, these packages are not thoroughly vetted, making them easy targets for attackers seeking to introduce malicious code into software supply chains. The npm ecosystem, cited in the scenario above, is particularly vulnerable. Often, these packages are not thoroughly vetted, making them easy targets for attackers seeking to introduce malicious code into software supply chains.

The Economic Impact of Cyber Threats

The economic impact of cyber threats is significant. Data breaches, ransomware attacks, and other cyber incidents can result in substantial financial losses for businesses. The costs associated with investigating and mitigating these incidents, as well as potential regulatory fines and legal fees, can be overwhelming. Additionally, the reputational damage caused by a cyber attack can have long-lasting effects on a company's bottom line.

For small and medium-sized businesses, the threat is even more severe. Often, these companies lack the resources necessary to implement advanced security solutions or to train staff on how to recognize and prevent cyber attacks. This makes them easy targets for hackers looking to exploit vulnerabilities in their systems.

The Challenges for Cybersecurity Teams

The evolution of threats described in the CrowdStrike 2026 report presents new challenges for cybersecurity teams. The need to manage an increasing volume of threat signals, many of which are generated by AI agents, requires new skills and tools. Additionally, the reduction in vulnerability exploitation times means that security teams must be able to respond quickly and effectively to prevent significant damage. Continuous training and skill updates are essential for cybersecurity professionals. Collaboration between internal teams and security solution providers is equally important to ensure a coordinated and timely response to emerging threats.

Future Perspectives and Recommendations

The CrowdStrike 2026 report underscores the importance of a proactive security strategy. Companies must adopt a risk-based approach, identifying and mitigating vulnerabilities before they can be exploited. The adoption of advanced security solutions, such as artificial intelligence and automation, can help reduce the workload for security teams and improve detection and response capabilities. Additionally, collaboration between the public and private sectors is crucial to addressing cyber threats. Sharing threat information and best practices can help improve the overall resilience of the cybersecurity landscape.

In conclusion, the CrowdStrike 2026 report provides a detailed overview of emerging threats in the cybersecurity landscape. Understanding these trends and adapting security strategies accordingly is essential to protect organizations from increasingly sophisticated cyber attacks.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the misuse of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.

📰 Source: crowdstrike.com ↗
✍️ Elaboration: Sebastiano · GoYou.it