Insider Spotlight
According to the company's draft 2026 Threat Hunting Report, attackers are exploiting trusted relationships across AI platforms, identities, endpoints and cloud environments while blending automated attacks with human-operated techniques. CrowdStrike said defenders must increasingly rely on intelligence-driven threat hunting and coordinated detection across multiple domains.
Why it matters
The findings suggest organizations face a rapidly shrinking window to detect and contain attacks as cybercriminals and state-sponsored actors adopt AI to automate reconnaissance, generate malware and accelerate vulnerability exploitation. The report also highlights growing risks to AI development environments as enterprises expand their use of generative AI.
CrowdStrike found zero-day exploitation increased 42 percent year over year between 2024 and 2025. From January to June 2026, 88 percent of vulnerabilities with publicly available proof-of-concept code were exploited within 48 hours of release, indicating attackers are weaponizing disclosed flaws much faster than in previous years.
The big picture
Software supply chain attacks have also evolved beyond malicious software packages to encompass AI software development kits, machine learning dependencies, model tooling and Model Context Protocol integrations.
CrowdStrike said these interconnected ecosystems increasingly contain valuable cloud credentials, API tokens and GPU infrastructure access, making them attractive targets.
The report noted that malicious npm packages accounted for 87 percent of identified malicious software packages during the first half of 2026.
It also identified North Korea-linked STARDUST CHOLLIMA and financially motivated cybercriminal ALTERED SPIDER among the most significant actors behind software supply chain compromises.
Voice phishing has likewise become a preferred initial access technique. CrowdStrike reported a 134 percent increase in vishing intrusions between 2024 and 2025, with the first half of 2026 already matching the number recorded during the second half of 2025.
The company said threat actors increasingly use fraudulent calls to persuade victims to launch remote access tools or compromise identity providers before expanding into cloud applications.
By the numbers
Technology remained the most targeted industry for the ninth consecutive year, followed by financial services, where intrusion activity rose 11 percent, and academe, which recorded the largest year-over-year increase at 17 percent.
Overall intrusion activity increased about 4 percent, a marked slowdown from the 27 percent growth reported a year earlier, reflecting what CrowdStrike described as a more mature threat landscape rather than reduced attacker activity.
The report concludes that proactive threat hunting, integrated telemetry and automation will be essential as attackers continue expanding across AI systems, cloud platforms and software supply chains while compressing the time available for defenders to respond. —Vanessa Hidalgo| Ed: Corrie S. Narisma