CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
Blog post from Crowdstrike
The CrowdStrike 2026 Threat Hunting Report highlights the evolving landscape of cybersecurity threats, with an emphasis on the increasing exploitation of trusted relationships and AI tools by adversaries. The report details how attackers are targeting identity systems, cloud environments, SaaS applications, and developer workflows to access critical assets before detection. Notably, AI has become both a tool and a target for adversaries, leading to more complex challenges for defenders. The report documents rapid exploitation of vulnerabilities, with adversaries acting within hours of public disclosures, and significant software supply chain attacks, particularly in open-source ecosystems. Noteworthy incidents include the use of AI-centric environments by DPRK-affiliated FAMOUS CHOLLIMA for sophisticated attacks on cryptocurrency firms and the exploitation of npm packages by adversaries like STARDUST CHOLLIMA. CrowdStrike's ongoing efforts to track and analyze over 290 adversaries are crucial for understanding and mitigating these threats, and the report provides essential insights for organizations to enhance their defensive strategies.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Agents | 3 | 1,180 | 266 | 113 | -80% |
| Secrets Management | 2 | 584 | 99 | 52 | -76% |
| Zero Trust | 2 | 42 | 18 | 10 | -81% |
| AI Coding Assistant | 1 | 276 | 77 | 47 | -83% |
| AI Guardrails | 1 | 96 | 30 | 18 | -81% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.