CrowdStrike’s 2026 Threat Hunting Report finds artificial intelligence is speeding up cyber attacks and forcing companies to change long-standing security practices. The report draws on data from July 2025 to June 2026. Attackers now weaponize 88 percent of newly disclosed vulnerabilities within 48 hours, often using AI to turn public proof-of-concept code into working exploits. The old 30-day patch window is gone. AI agent activity now triggers 2.5 times more detections than human users. Software supply chains face heavy pressure, with hundreds of dependencies compromised in a single day and most malicious registry threats tied to npm packages. Attackers also target AI systems themselves through credential theft, LLM jacking and cost harvesting. Technology firms remain the top target. CrowdStrike says organizations must secure AI environments, identities, cloud systems and supply chains while moving to much faster vulnerability response.
CrowdStrike’s 2026 Threat Hunting Report finds artificial intelligence is speeding up cyber attacks and forcing companies to change long-standing security practices. The report draws on data from July 2025 to June 2026. Attackers now weaponize 88 percent of newly disclosed vulnerabilities within 48 hours, often using AI to turn public proof-of-concept code into working exploits. The old 30-day patch window is gone. AI agent activity now triggers 2.5 times more detections than human users. Software supply chains face heavy pressure, with hundreds of dependencies compromised in a single day and most malicious registry threats tied to npm packages. Attackers also target AI systems themselves through credential theft, LLM jacking and cost harvesting. Technology firms remain the top target. CrowdStrike says organizations must secure AI environments, identities, cloud systems and supply chains while moving to much faster vulnerability response.