CrowdStrike 2026 Threat Hunting Report: AI is Now Embedded Across Modern Adversary Operations
Threat actors operationalize AI to exploit vulnerabilities within hours, target enterprise AI, and scale attacks across software supply chains
CrowdStrike (NASDAQ: CRWD) today released the 2026 Threat Hunting Report, revealing that AI is now embedded across modern adversary operations. China-nexus adversaries exploited critical vulnerabilities within 24 hours of public proof-of-concept (PoC) release, while DPRK-nexus adversaries poisoned 131 trusted AI framework packages, demonstrating how AI has become both an operational capability and a high-value target.
AI is now a tool, target, and force multiplier for adversaries. As enterprises embed AI across their business, adversaries are exploiting AI infrastructure, compromising software supply chains, abusing enterprise LLMs, and following AI workloads into the cloud. The result is a new operational reality: attacks move faster, scale more efficiently, and increasingly target the AI systems enterprises depend on.
CrowdStrike Threat Hunting Report Highlights:







