Hackers are shrinking the time between a software flaw becoming public and a real attack to mere hours, and artificial intelligence is helping them move even faster, according to CrowdStrike’s new 2026 Threat Hunting Report.
The cybersecurity company said AI has become both a target and a weapon for attackers. Threat groups are using AI to generate malicious code, automate parts of their operations, abuse enterprise AI systems, and target the software supply chains that many companies rely on.
One campaign highlighted by CrowdStrike sent nearly 200,000 requests to an AI model service in just two minutes, demonstrating how quickly attackers can abuse enterprise AI infrastructure.
“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” said Adam Meyers, head of counter adversary operations at CrowdStrike.
CrowdStrike also found that AI agent-triggered detection leads are appearing at 2.5 times the rate of human-triggered leads, increasing the amount of activity security teams must investigate.
Patch windows are collapsing
The report’s most striking finding is how quickly attackers are exploiting newly disclosed vulnerabilities.
During the first half of 2026, 88% of the vulnerability exploitation observed by CrowdStrike involving public proof-of-concept code occurred within 48 hours of the code’s release. China-linked groups VAULT PANDA and GENESIS PANDA moved even faster, launching what CrowdStrike called “deliberate attacks” within 24 hours of disclosure.
The company said this trend is likely to continue as advanced AI systems make vulnerability discovery and exploit development faster.
Trusted systems are becoming attack paths
CrowdStrike said attackers are increasingly abusing legitimate authentication systems, cloud identities, and software-as-a-service applications instead of relying on traditional malware.
Vishing intrusions doubled during the first half of 2026, while monthly device-code phishing attempts increased 15-fold, according to CrowdStrike. In one incident, the eCrime group SNARKY SPIDER moved from taking over an account to stealing data in under five minutes. Cloud-focused cybercrime activity also surged 171% during the reporting period.
The software supply chain is under pressure
Attackers are targeting package registries, developer tools, and AI frameworks to reach downstream victims.
CrowdStrike said 87% of identified software registry threats in the first half of 2026 involved malicious npm packages. The company also linked North Korean group STARDUST CHOLLIMA to attacks that compromised more than 130 AI framework packages.
More must-read AI coverage
- SS&C Intralinks DealCentre AI vs. Datasite: Which platform is built for the future of dealmaking?
- SS&C Intralinks FundCentre AI vs. Juniper Square: Which platform better supports modern private markets fund managers?
- Why Data, Not Models, Determines AI Success
- The Rise of the AI-Native Factory: How Physical AI Is Transforming Manufacturing
What this means for companies
The report suggests that many organizations can no longer rely on traditional patch cycles or perimeter-focused defenses. The most vulnerable points are increasingly the tools employees trust every day — cloud accounts, single sign-on systems, AI services, and software dependencies.
For businesses adopting AI quickly, AI deployment without strong identity controls, monitoring, and software supply chain protections could create new risks faster than security teams can respond.
“The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary,” Meyers said.
Read more: Five Eyes agencies warn that AI could accelerate cyberattacks within months, increasing pressure on organizations to strengthen access controls, patch faster, and prepare for shrinking response windows.