Artificial intelligence is becoming deeply embedded in cyberattacks, helping adversaries accelerate operations while creating new targets across enterprise AI infrastructure, software supply chains, and cloud environments, according to CrowdStrike’s 2026 Threat Hunting Report.
Based on intelligence from CrowdStrike threat hunters and analysts tracking more than 290 named adversaries, the report found that attackers are increasingly using AI to generate malicious payloads and shell commands, exploit AI infrastructure, and abuse enterprise large language models (LLMs).
In one campaign, attackers generated nearly 200,000 requests to an AI model in just two minutes. CrowdStrike also reported that detection leads triggered by AI agents grew 2.5 times faster than those triggered by humans, highlighting the increasing volume and speed of activity security teams must investigate.
The AI software ecosystem is also emerging as a new supply chain target. A DPRK-nexus threat actor compromised a malicious npm package that was injected into 131 trusted Mastra AI framework packages. During the first half of 2026, 87% of identified software registry threats involved malicious npm packages.
Attackers are also exploiting software vulnerabilities at unprecedented speed. CrowdStrike found that 88% of observed exploitation involving vulnerabilities with publicly available proof-of-concept code occurred within 48 hours of release. China-nexus adversaries launched deliberate attacks within 24 hours of vulnerability disclosure.
Cloud environments are another growing target as organizations deploy more AI workloads. Cloud-focused eCrime activity surged 171%, with attackers pursuing credentials, cryptomining opportunities, LLM abuse, and digital financial assets.
The report also identified growing attacks against trusted authentication systems. Vishing intrusions doubled during the first half of 2026, while monthly device-code phishing attempts increased 15-fold. In one incident, attackers moved from compromising an account to stealing data in less than five minutes after gaining access to a single sign-on-integrated SaaS application.
CrowdStrike said the findings demonstrate that organizations must treat AI security as an essential part of broader cybersecurity strategies. As enterprises increasingly depend on AI, attackers are simultaneously adopting the technology to increase the speed, scale, and effectiveness of their operations.
“AI is now embedded in modern adversary operations,” said Adam Meyers, head of counter adversary operations at CrowdStrike. He said organizations need to secure AI as aggressively as they adopt it and use AI to defend at the speed of increasingly automated adversaries.
The report underscores a growing cybersecurity challenge: AI is no longer simply another enterprise technology to protect. It is becoming part of the infrastructure, software ecosystem, and operational workflows that attackers actively target and exploit.


