CrowdStrike report flags AI-driven cyberattacks shrinking vulnerability exploitation window to hours
CRWD•CrowdStrike 2026 Threat Hunting Report highlights faster AI-driven attacks
CrowdStrike’s 2026 Threat Hunting Report flagged AI as embedded across adversary operations, accelerating attack speed while expanding enterprise attack surfaces.
- In 1H 2026, 88% of observed exploitation of vulnerabilities with public PoC occurred within 48 hours; China-nexus actors attacked within 24 hours.
- DPRK-nexus actors poisoned 131 trusted AI framework packages; 87% of identified software registry threats involved malicious npm packages.
- Cloud-conscious eCrime activity surged 171%, reflecting increased targeting of AI workloads and cloud environments.
- Vishing intrusions doubled; device code phishing attempts rose 15x, highlighting growing abuse of trusted authentication workflows and SSO-linked SaaS.




