Report by CrowdStrike

CrowdStrike 2026 Threat Hunting Report

12 FINDINGSPublished Aug 3, 2026
View Original Report →

Key Findings

Vishing intrusions increased by 2x in 1H 2026.

PhishingSocial EngineeringVishing

SNARKY SPIDER moved from account takeover to data theft in under five minutes in one incident.

Account TakeoverData Theft

China-nexus adversaries exploited critical vulnerabilities within 24 hours of public proof-of-concept release.

Vulnerability ExploitationState-Sponsored Threats

DPRK-nexus adversaries injected malicious packages into AI frameworks, poisoning 131 trusted AI framework packages.

Supply Chain SecurityAI FrameworksState-Sponsored Threats

One campaign sent nearly 200,000 AI model requests in two minutes.

AI Abuse

AI agent-triggered detection leads grew at 2.5x the rate of human-triggered leads.

Threat DetectionAISecurity Operations

In 1H 2026, 87% of identified software registry threats involved malicious npm packages.

Software Supply ChainMalicious Packagesnpm

eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.

Supply Chain SecurityCredential Theft

Monthly device code phishing attempts increased 15x in 1H 2026.

PhishingAuthentication

Cloud-conscious eCrime activity surged 171% as adversaries executed credential theft, cryptomining, LLM abuse, and digital financial asset theft.

Cloud SecurityeCrimeCryptominingLLM Abuse

In 1H 2026, 88% of observed exploitation of vulnerabilities with a public PoC occured within 48 hours of release.

Vulnerability ExploitationTime-to-Exploit

China-nexus actors VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of disclosure.

State-Sponsored ThreatsVulnerability Exploitation