CrowdStrike’s annual Threat Hunting Report, published August 3, 2026, identifies a structural change in adversarial operations that applies across all sectors Adversary Wire tracks. AI is no longer an emerging capability in threat actor toolkits: it is now embedded in modern adversary operations at the operational level. Concurrently, the window between vulnerability disclosure and active exploitation has effectively closed, and state-linked actors are targeting the AI supply chain with deliberate package poisoning campaigns.
Key Findings
Exploitation speed has reached near-zero. CrowdStrike documented that 88% of publicly disclosed vulnerability exploits in H1 2026 resulted in active intrusions within 48 hours of disclosure. China-nexus adversaries are moving particularly fast, in several documented cases exploiting critical vulnerabilities within 24 hours of proof-of-concept code becoming available. This eliminates any meaningful window between patch release and exploitation for most enterprise patch cycles, which operate on weekly or monthly cadences. The practical implication is that patch-on-schedule policies are structurally inadequate for critical vulnerabilities; emergency patching protocols are now the expected baseline.
STARDUST CHOLLIMA poisoned 131 AI framework packages. The North Korean intrusion set STARDUST CHOLLIMA, which CrowdStrike has previously documented targeting cryptocurrency platforms and software supply chains, conducted a sustained campaign against the npm ecosystem that resulted in 131 trusted AI framework packages being compromised. This is a significant escalation in DPRK-nexus targeting of the AI software supply chain: prior campaigns primarily targeted financial platforms and individual developer credentials. The targeting of AI framework packages suggests a strategic interest in either access to organisations deploying AI infrastructure or the ability to introduce persistence into AI pipeline dependencies. 87% of all malicious software-registry threats identified in the report period originated from npm packages.
Vishing doubled in H1 2026. Voice-based social engineering intrusions more than doubled in the first half of 2026 compared to the second half of 2025. This growth is consistent with AI voice synthesis becoming operationally reliable for adversary use: the same pattern CrowdStrike identified in 2025 as an emerging technique has accelerated into a mainstream intrusion vector. Vishing campaigns targeting IT helpdesks and MFA reset workflows — a technique most prominently associated with Scattered Spider — are now being replicated by a broader set of actors.
Cloud-targeted criminal activity increased 171%. eCrime actors increased cloud-focused activity substantially, consistent with enterprise migration to cloud environments expanding the attack surface. The techniques involved include credential theft, misconfiguration exploitation, and lateral movement across cloud service boundaries once initial access is established.
AI is augmenting threat detection on both sides. AI agent-triggered detection leads grew 2.5 times faster than human-triggered detection leads during the report period. This reflects both the deployment of AI-assisted hunting tools and the ability of AI agents to process at scale the kind of low-signal indicators that would be missed in manual review. The same capability growth applies to adversary tooling: CrowdStrike assesses that AI is now routinely used for target reconnaissance, social engineering content generation, and code modification to evade static analysis.
Sector Implications
Finance and professional services face the most direct exposure from the vishing escalation, given the prevalence of helpdesk and IT support social engineering targeting high-privilege account resets.
Critical infrastructure operators face the 24-hour exploitation window as the primary concern: industrial control systems and OT environments frequently cannot be patched on emergency timelines due to uptime requirements and change-control processes designed for stability rather than agility.
Healthcare and research organisations should treat the STARDUST CHOLLIMA npm campaign as directly relevant: AI-assisted diagnostic, research pipeline, and workflow tools frequently use Python and Node.js ecosystems where npm packages are a common dependency.
Communications and technology providers face cloud targeting as the core risk, given high cloud adoption and the value of provider access for downstream customer targeting.
Recommended Actions
- Implement vulnerability triage processes that can distinguish critical vulnerabilities requiring emergency patching from standard cadence items. The 48-hour exploitation window does not apply uniformly; it applies to high-value, widely-deployed software with public PoC code.
- Audit npm dependencies in AI pipelines and research tooling against current threat intelligence. STARDUST CHOLLIMA’s campaign is ongoing.
- Harden helpdesk identity verification processes against vishing: out-of-band callbacks, manager approval for sensitive account actions, and video verification for MFA resets are the relevant controls.
- Review cloud environment logging and anomaly detection coverage. Cloud-focused criminal activity is increasing faster than most cloud security programmes are maturing.