CrowdStrike report: AI is rewriting rules of cybersecurity
Mon, 3rd Aug 2026 (Yesterday)
Artificial intelligence is significantly accelerating the speed and scale of cyber attacks, forcing organisations to rethink long-standing security practices as attackers exploit software vulnerabilities within hours, rather than weeks.
AI has become both a powerful tool for cyber criminals and an increasingly attractive target itself, creating new risks for enterprises adopting AI technologies.
This rapid advance in attacking capabilities poses a significant threat for technology companies.
As the CrowdStrike 2026 Threat Hunting Report is released, CrowdStrike Senior VP Counter Adversary, Adam Meyers, spoke about its illuminating findings.
"The same AI tools driving modern businesses are creating under-defended attack surfaces that adversaries are exploiting," Meyers said.
The report, which draws on telemetry from CrowdStrike's managed threat hunting team OverWatch between July 2025 and June 2026, is based on more than seven trillion security events processed daily.
Those events are distilled into approximately 14 million daily detection leads before resulting in around 36,000 customer alerts each year.
One of the most significant findings is the rapid increase in AI-generated activity across enterprise environments.
The company found AI agent-driven behaviour now triggers 2.5 times more detections than human users, reflecting the widespread deployment of coding assistants, autonomous software agents and AI-powered business tools.
Organisations are increasingly running AI services, such as coding assistants, directly on corporate endpoints, giving security teams visibility into how AI systems interact with enterprise environments.
"We can actually tie that all back. What that allows us to do is see detections not just from humans, but also detections triggered by machines and automation," he said.
Patch windows collapse
One of the most concerning trends identified in the report is the large reduction in the time organisations have to respond to newly disclosed software vulnerabilities.
CrowdStrike found that 88 per cent of vulnerabilities are now being weaponised within 48 hours of disclosure, largely due to attackers using AI to rapidly analyse publicly released proof-of-concept exploits and generate working attack code.
"The 30-day patch window... is completely obsolete," Meyers said.
"We're down to 24-hour, 48-hour patch cycles, and organisations are really struggling under that."
The scale of the problem is also growing rapidly. More than 43,000 common vulnerabilities and exposures had already been registered in the year to date, quickly approaching the approximately 48,200 recorded in all of 2025.
In June alone, more than 7400 vulnerabilities were disclosed, representing a 96 per cent year-on-year increase.
The report highlights several examples illustrating just how quickly attackers now move.
One vulnerability dubbed React2Shell was first exploited within five hours of public disclosure before multiple China-linked threat groups adopted it within the following two days.
Another vulnerability, Copy Fail, was observed being exploited by a threat actor linked with Belarus, against a Ukrainian government organisation just 20 hours after details became public.
AI-assisted research is increasingly shortening the time between vulnerability disclosure and real-world attacks.
Software supply chains under attack
The report also warns that AI development ecosystems have become major targets for cyber criminals and nation-state actors.
The company observed more than 300 software dependencies being compromised in a single day by the North Korean group Altered Spider, while 87 per cent of malicious software registry threats involved npm packages commonly used by software developers.
Rather than targeting end users directly, attackers are increasingly compromising continuous integration and deployment pipelines, software repositories and development tools before pivoting into customer environments.
"The AI ecosystem is the next software supply chain battleground," Meyers said.
He described AI development infrastructure as one of the highest-value attack surfaces currently available to adversaries because compromising a developer or software package can provide downstream access to numerous organisations simultaneously.
Voice-based phishing surges
Traditional phishing emails are also being supplemented by more sophisticated voice-based phishing.
CrowdStrike recorded a 100 per cent increase in voice phishing intrusions during the first half of 2026 compared with the second half of 2025.
Attackers typically call help desks or employees while directing victims to fake login pages that capture credentials. Once inside an organisation, threat actors rapidly register their own multi-factor authentication devices before accessing cloud services and extracting sensitive data.
Experienced attackers can move from account takeover to data theft in under five minutes.
Because these attacks involve legitimate credentials rather than malware, they often leave very little forensic evidence and bypass many traditional endpoint security controls.
The report also documents a 171 per cent increase in cloud-focused e-crime activity and a rise in device-code phishing attacks targeting users' mobile devices and cloud identities by a factor of 15.
AI becomes weapon and target
Beyond helping attackers move faster, AI is increasingly being exploited directly.
Threat actors are stealing credentials for commercial AI models, hijacking enterprise AI resources and abusing customers' computing credits through attacks CrowdStrike describes as LLM jacking and cost harvesting.
At the same time, attackers are targeting AI infrastructure itself, including open-source frameworks and language model platforms, to deploy malware or ransomware.
AI should now be treated as a critical enterprise asset requiring the same level of protection as traditional corporate infrastructure.
"We've seen AI is a high-value attack surface, and it's being used by more and more threat actors," Meyers said.
Travelling executives face growing risks
The report identified a sophisticated campaign involving physical access attacks against travelling executives and specialists attending conferences.
CrowdStrike detailed an operation credited to China-linked threat actor Overcast Panda, in which hotel rooms were reportedly accessed while attendees were enjoying dinner during a conference in Hainan Island.
Attackers allegedly booted victims' laptops from USB devices before installing persistent malware capable of providing covert remote access after the travellers returned home.
Companies are being advised to provide executives with dedicated travel laptops and phones containing minimal sensitive information in this new physical threat landscape.
"This is something organisations really need to consider," Meyers said.
Tech remains the biggest target
For the ninth consecutive year, technology companies remained the most heavily targeted industry, reflecting their central role in global digital infrastructure.
The academic sector recorded the largest increase in attacks, rising 17 per cent year on year, while nation-state activity targeting financial services increased by 29 per cent.
CrowdStrike also identified 10 new adversary groups during the reporting period, including North Korea, Russia and Belarus-linked operators, alongside emerging cybercriminal gangs filling the void left by recent action against Scattered Spider.
Looking ahead, organisations must fundamentally rethink cyber defence by securing AI environments, strengthening identity protection, improving visibility across cloud and SaaS environments, securing software supply chains and accelerating vulnerability management.
"Know the adversary, understand who these threat actors are, how they operate, what they're after," Meyers said.
"That's the best way to defend against these types of attacks."