CrowdStrike Report: AI, Supply Chains, and Trusted Identities Fuel Rising Cyber Threats
CrowdStrike's 2026 Threat Hunting Report reveals a 4% increase in cyber intrusion activity, driven by attackers exploiting AI tools, software supply chains, and compromised identities.

Cybercriminals and state-backed hacking groups are increasingly leveraging trusted identities, cloud services, artificial intelligence (AI) tools, and software supply chains to gain unauthorized access while actively evading detection. This trend is highlighted in CrowdStrike’s 2026 Threat Hunting Report, which indicates a roughly 4% rise in cyber intrusion activity over the past year. While this growth is less pronounced than in the previous reporting period, it signifies a strategic shift by adversaries towards more targeted campaigns, investing greater effort into abusing legitimate infrastructure and access paths to achieve stealthier intrusions.
The report details how threat actors are harnessing the power of Large Language Models (LLMs) to accelerate their operations. These AI tools are being used to generate malicious code, craft sophisticated phishing emails, automate reconnaissance tasks, and create scripts for post-compromise activities. Furthermore, AI is proving instrumental in identifying vulnerabilities, developing proof-of-concept (PoC) exploits, and significantly shortening the window between a vulnerability's disclosure and its active exploitation. "AI is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend," stated Adam Meyers, head of counter adversary operations at CrowdStrike. He emphasized that successful organizations will need to secure AI adoption as aggressively as they embrace its capabilities, while simultaneously employing AI to defend against adversaries operating at machine speed.
Specific examples of AI abuse include attackers exploiting AI server software to exfiltrate sensitive configuration data and deploy cryptocurrency miners. Financially motivated groups have been observed abusing enterprise AI platforms in attacks known as LLMJacking, where one incident saw attackers gain administrative access to a cloud account and initiate nearly 200,000 LLM requests within two minutes, consuming substantial AI resources at the victim's expense.
Adversaries are demonstrating an alarming agility in exploiting newly disclosed vulnerabilities. Between January and June 2026, a staggering 88% of observed exploitation attempts involving vulnerabilities with publicly available PoC code occurred within 48 hours of their release. In one notable instance, China-linked groups launched attacks within 24 hours of a critical web application vulnerability being disclosed, underscoring the urgency for rapid patching.
The software supply chain remains a prime target for attackers. Threat actors are actively hiding malware within software packages uploaded to public repositories frequented by developers. Once these malicious packages are installed, they can distribute harmful code to thousands of downstream users. The npm package registry, in particular, accounted for 87% of malicious software packages identified during the reporting period. Attackers are compromising package registries, CI/CD pipelines, container registries, and IDE extensions, recognizing these as critical gateways to production systems, cloud environments, and customer networks.
Two specific groups, the North Korea-linked STARDUST CHOLLIMA and the financially motivated ALTERED SPIDER, were identified as the most active in software supply chain attacks. One ALTERED SPIDER campaign reportedly compromised over 300 software dependencies in a single day, enabling the group to steal credentials and gain access to cloud environments.
Vishing, or voice phishing, has emerged as one of the fastest-growing methods for initial access. Attackers impersonate IT support personnel over the phone, manipulating employees into entering their credentials on fake login pages or approving remote access via legitimate software like Microsoft Quick Assist. Because these attacks often leverage valid credentials, they frequently bypass traditional security detection tools. Vishing-related intrusions saw a significant 134% increase between 2024 and 2025, with activity accelerating further in the first half of 2026.
Cloud-focused cybercrime activity surged by 171% over the past year, primarily driven by credential theft, cryptocurrency mining, AI service abuse, and efforts to pilfer digital assets. Device code phishing, which exploits Microsoft's legitimate authentication process, is a rapidly growing technique, with attempts increasing 15-fold in the past six months. Attackers are increasingly targeting cloud credentials, API keys, and secrets stored within cloud services to access cryptocurrency wallets and other high-value assets. Detecting these intrusions often relies on identifying anomalous cloud activity, as attackers frequently utilize legitimate accounts and authentication tokens.