The CrowdStrike 2026 Threat Hunting Report documents a shift toward trust abuse across identity, cloud, SaaS, AI, and software supply chain attack surfaces. Adversaries are compressing vulnerability exploitation windows to under 24 hours, leveraging vishing and device code phishing for rapid account takeover, and compromising npm package ecosystems to deliver malware downstream. AI services are both targets (LLMJacking, AI supply chain compromise) and accelerants, with AI agent-triggered detections surfacing 2.5x more threat leads than manual activity.
LLMJacking
1 post
CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates