Artificial Intelligence Is the Weapon and the Target, CrowdStrike Report Finds
By Sara Mosqueda
4 August 2026
Attackers continue to abuse organizational trust to gain initial access to a system and move through it without detection. This trend has continued from 2025, with attackers targeting supply chain partners, upstream developer ecosystems, legitimate software, and employees, according to CrowdStrike’s 2026 Threat Hunting Report
CrowdStrike’s threat hunting team sifts through massive amounts of data every day, identifying more than 14 million daily detection leads for additional analysis. This translates to more than 36,000 annual customer notifications and alerts, with each alert representing a likely malicious incident
While artificial intelligence (AI) helps deal with the immense volume of attacks, the irony in the current environment is that AI is what is also helping attackers. Attackers are using AI to “accelerate phishing, reconnaissance, and technical operations and targeting the AI systems now embedded across the enterprise,” the report said
This report focused on the coordination of interactive intrusions and automated attacks, with the two elements presenting a cohesive threat. Whether it’s a nation-state group or an attacker motivated by money, sophisticated threat actors are increasingly blending scalable automation with traditional hands-on tactics to maximize impact and escape immediate detection, according to the report
During the first six months of 2026, CrowdStrike noted that 88 percent of observed exploitation of vulnerabilities involving a public proof of concept occurred within 48 hours from when the weakness was publicly disclosed, meaning security teams are dealing with a smaller window of opportunity to handle vulnerabilities once they become public
Threat actors with links to China were even quicker to respond. Cyber adversary groups VAULT PANDA and GENESIS PANDA were observed launching deliberate attacks within 24 hours of the announcement of a critical Web application vulnerability After the vulnerability was announced, CrowdStrike’s OverWatch was dealing with more than 800 leads from more than 80 victims within four days
The top sectors targeted in these hybrid attacks were technology, consulting and professional services, financial services, manufacturing, and retail. The least targeted were industrials and engineering, academia, telecommunications, government, and healthcare. Technology, given its fundamental connection to trusted digital ecosystems, remains the most-targeted industry
Beyond industries, attackers are also focusing on AI’s software ecosystem due to the convergence of software development and AI workflows. Being able to compromise a software supply chain is hinges on an attacker abusing developer identities and privileged credentials. Hoping to avoid traditional security controls, software supply chain attacks have increasingly involved attempts to introduce malicious software packages to public software registries. Those registries are used by developers and organizations in all industries and geographies.
“Malicious packages can reach hundreds of thousands of systems within hours of publication, representing a scale of compromise that is nearly impossible for network defenders to fully assess in real time,” the report said.
As for methods, the most common way that attackers incorporated AI was by using AI to create reused after gaining access to a system
But the most advanced use of AI came from the threat actor group FAMOUS CHOLLIMA, which created whole fake companies that had AI-generated websites, GitHub accounts, and email infrastructure—all made to support the group’s activities

