SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
CrowdStrike says AI is now central to cyberattacks

CrowdStrike says AI is now central to cyberattacks

Mon, 3rd Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

CrowdStrike has released its 2026 Threat Hunting Report, which finds that artificial intelligence is now embedded across modern adversary operations.

Attackers are using AI to shorten the gap between public vulnerability disclosure and active exploitation, while also targeting AI systems and software supply chains.

Drawing on tracking of more than 290 named adversaries by CrowdStrike threat hunters and intelligence analysts, the report describes AI as both a tool for attackers and a target in its own right. Enterprises are facing attacks on AI infrastructure, abuse of large language models, and efforts to compromise the software dependencies that support AI workloads.

One of the central findings is the speed of exploitation after proof-of-concept code becomes public. In the first half of 2026, 88% of the exploitation CrowdStrike observed for vulnerabilities with a proof of concept took place within 48 hours of release.

China-linked actors identified as Vault Panda and Genesis Panda moved faster still, launching attacks within 24 hours of disclosure. The trend points to a shrinking response window for corporate security teams once a vulnerability becomes publicly actionable.

Supply chain risks

The report also highlights attacks on the AI software ecosystem. A DPRK-linked group tracked as Stardust Chollima inserted a malicious npm package into 131 trusted Mastra AI frameworks.

In the first half of the year, 87% of identified software registry threats involved malicious npm packages. The report also cites activity by an eCrime actor known as Altered Spider, which compromised more than 300 software dependencies in a single day to steal credentials and gain access to cloud environments.

This focus on package repositories and dependency chains reflects a broader shift in attacker behaviour. Rather than targeting only end-user devices or corporate networks, threat actors are increasingly seeking access through the components developers rely on to build and deploy software, including AI applications.

Cloud and identity

Cloud-focused eCrime activity rose 171% as attackers pursued credential theft, cryptomining, abuse of large language models, and theft of digital financial assets. Adversaries are following enterprise AI deployments into cloud environments, where data, models, and services are concentrated.

The report also points to rising misuse of trusted authentication systems. Vishing intrusions doubled in the first half of 2026, while monthly device code phishing attempts increased 15-fold over the same period.

Groups identified as Cordial Spider and Snarky Spider were found to have compromised single sign-on-integrated software-as-a-service applications for data theft. In one case cited in the report, Snarky Spider moved from account takeover to data exfiltration in under five minutes.

The findings suggest identity systems are becoming a primary route for intrusion as attackers look for faster ways to bypass perimeter defences. By abusing approved login flows and SaaS integrations, intruders can gain access without relying on more traditional malware delivery methods.

AI in operations

Threat actors used AI to generate payloads and shell commands, exploit AI infrastructure, and abuse enterprise large language models. The report cites one campaign that sent nearly 200,000 AI model requests in two minutes.

CrowdStrike also said AI agent-triggered detection leads grew at 2.5 times the rate of human-triggered leads. This indicates security teams are contending with a higher volume and speed of suspicious activity linked to automated systems.

For defenders, the report paints a picture of compressed timelines and broader exposure. Vulnerability management, software supply chain monitoring, identity protection, and cloud security now overlap more directly with AI adoption than in previous reporting cycles.

Adam Meyers, Head of Counter Adversary Operations at CrowdStrike, commented on the findings.

"AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend," said Adam Meyers, Head of Counter Adversary Operations at CrowdStrike.

"The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary," Meyers said.