CYBERSECURITY THREAT INTELLIGENCE

AI Cyber Threats Surge 89% as Attackers Pivot Strategy

TM
Techmediaglobal
| 5 min read
89%
RISE IN AI-ENABLED ADVERSARY ACTIVITY
88%
PoC BUGS EXPLOITED WITHIN 48 HRS
87%
SUPPLY CHAIN ATTACKS VIA npm
7tn+
SIGNALS ANALYSED DAILY

AI-enabled adversary activity has jumped 89% over the past year, according to CrowdStrike's 2026 Threat Hunting Report. Drawing on more than seven trillion daily signals from its OverWatch platform, the report paints a picture of attackers who are exploiting vulnerabilities faster, weaponising AI infrastructure itself, and poisoning open-source software supply chains at unprecedented scale.

Adversary Activity Shows Slower Growth

Overall adversary activity rose just 4% this year, well down from the 27% growth recorded the year before. CrowdStrike suggests this plateau signals a maturing threat landscape rather than a retreat by attackers.

Rather than relying on brute-force campaigns, adversaries are increasingly investing in more sophisticated methods of gaining initial access. The shift points to a change in strategy — quality over quantity — rather than any drop in capability.

Meanwhile, the exploitation window keeps shrinking: between January and June 2026, 88% of vulnerabilities with publicly available proof-of-concept code were actively exploited within just 48 hours of release.

AI Environments Become Attack Vectors

Famous Chollima, a threat actor linked to the Democratic People's Republic of Korea, targeted cryptocurrency and blockchain firms through trusted AI environments, showing the most advanced AI tradecraft observed by CrowdStrike this year. The group built entire fake companies — complete with AI-generated websites, GitHub accounts and email infrastructure — far exceeding a typical phishing operation.

Separately, financially motivated actors carried out what CrowdStrike terms "LLMjacking": stealing or exploiting cloud credentials and API keys to hijack an organisation's AI models. Victims are then hit with steep bills from AI providers — in one case, attackers fired off 200,000 model requests in just two minutes.

CrowdStrike also observed adversaries exploiting flaws in AI-related server software, using compromised systems for cryptocurrency mining and to gather intelligence on sensitive configurations.

"AI is now a tool, a target and a force multiplier for adversaries."

CrowdStrike, 2026 Threat Hunting Report

Software Supply Chains Face Persistent Threats

Between July 2025 and July 2026, Node Package Manager (npm) packages accounted for 87% of all software supply chain poisoning attacks. CrowdStrike points to npm's deep dependency trees, its habit of auto-running install scripts, and JavaScript's broad popularity as reasons the ecosystem is such an attractive target.

Millions of users rely on packages distributed through the npm registry, and attackers are increasingly treating that inherent developer trust as a systemic weak point — targeting dependencies, tooling, registries and IDE extensions, and using automation to scale their reach.

The threat actor tracked as Altered Spider (TeamPCP) deployed a self-propagating worm earlier in 2026 that stole credentials and autonomously published further infected packages across both the npm and PyPI ecosystems, entirely without human intervention. A single set of stolen maintainer credentials was enough for the group to compromise more than 300 dependencies within a single day in May 2026.

China-Nexus Actors Demonstrate Speed

CrowdStrike singles out Overcast Panda as one of the most operationally sophisticated threats facing organisations with staff travelling to China, relying on physical proximity to target devices to bypass network-based defences, endpoint detection and user training entirely.

Two further China-nexus groups, Vault Panda and Genesis Panda, weaponised vulnerabilities within 24 hours of proof-of-concept disclosure. Adam Meyers, Head of Counter Adversary Operations at CrowdStrike, links the activity to China's strategic push to acquire manufacturing, chip-design and nuclear-related technologies from countries such as Germany, the Netherlands and the UK through economic espionage.

Key Takeaways

  • AI-enabled adversary activity rose 89% year-on-year, per CrowdStrike's 2026 Threat Hunting Report.
  • 88% of vulnerabilities with public proof-of-concept code were exploited within 48 hours in H1 2026.
  • DPRK-linked Famous Chollima built fake companies with AI-generated infrastructure to target crypto firms.
  • "LLMjacking" attacks hijack stolen cloud credentials to run up massive unauthorised AI usage bills.
  • npm packages accounted for 87% of software supply chain poisoning attacks over the past year.
  • China-nexus groups like Overcast Panda, Vault Panda and Genesis Panda are weaponising exploits within hours.
Tags: CrowdStrike Cybersecurity Threat Intelligence Supply Chain Security Nation-State Actors LLMjacking China