CrowdStrike finds AI systems under direct attack as exploit windows shrink

Artificial intelligence has become a target for attackers rather than only a tool they use, according to CrowdStrike Holdings Inc.’s “2026 Threat Hunting Report,” released today.

The annual report draws on observations from CrowdStrike’s OverWatch threat hunting team and intelligence analysts tracking more than 290 named adversaries over the 12 months to June 30. Previous editions counted only interactive, hands-on-keyboard intrusions. This year’s also folds in automated attacks, a methodology change CrowdStrike says gives a more accurate picture of how adversaries now operate.

CrowdStrike now measures the exploitation window in hours rather than days. It counted the gap between a proof-of-concept exploit going public and attackers picking it up. Between January and June, that gap came in under 48 hours in 88% of cases, and the year before, zero-day exploitation had risen 42%.

Two China-nexus groups beat even that. React2Shell (CVE-2025-55182), an unauthenticated remote code execution flaw in React Server Components and Next.js, was disclosed alongside patches on Dec. 3, 2025. Working exploit code appeared the next day. Vault Panda and Genesis Panda were attacking within 24 hours. OverWatch chased more than 800 hunting leads at more than 80 victims in the first four days.