CrowdStrike finds AI systems under direct attack as exploit windows shrink Artificial intelligence has become a target for attackers rather than only a tool they use, according to CrowdStrike Holdings Inc.’s “2026 Threat Hunting Report,” released today. The annual report draws on observations from CrowdStrike’s OverWatch threat hunting team and intelligence analysts tracking more than 290 named adversaries over the 12 months to June 30. Previous editions counted only interactive, hands-on-keyboard intrusions. This year’s also folds in automated attacks, a methodology change CrowdStrike says gives a more accurate picture of how adversaries now operate. CrowdStrike now measures the exploitation window in hours rather than days. It counted the gap between a proof-of-concept exploit going public and attackers picking it up. Between January and June, that gap came in under 48 hours in 88% of cases, and the year before, zero-day exploitation had risen 42%. Two China-nexus groups beat even that. React2Shell (CVE-2025-55182), an unauthenticated remote code execution flaw in React Server Components and Next.js, was disclosed alongside patches on Dec. 3, 2025. Working exploit code appeared the next day. Vault Panda and Genesis Panda were attacking within 24 hours. OverWatch chased more than 800 hunting leads at more than 80 victims in the first four days. AI infrastructure itself is now being probed directly. AI model access techniques accounted for 16% of the MITRE ATLAS techniques CrowdStrike observed over the year. The company’s honeypot infrastructure captured one exploit payload carrying a malicious Model Context Protocol server configuration, built to read a parent process’s environment variables and send configuration data to an external webhook. Corporate large language model access is being hijacked outright, a practice the report calls LLMjacking. In a May campaign against a cloud provider’s foundation model service, a threat actor escalated a compromised identity to administrator privileges and submitted the use-case form required to unlock model access. It then sent nearly 200,000 application programming interface requests in an initial two-minute flood before throttling kicked in. Adversaries are using the technology as much as they are attacking it. Famous Chollima, the North Korean group behind large-scale IT worker infiltration, built entire fake companies with AI-generated websites, GitHub accounts and email infrastructure to support insider operations. AI agent-triggered detection leads now arrive at 2.5 times the rate of human-triggered leads, OverWatch said. Software registries remain the shortest path into developer environments. Malicious npm packages accounted for 87% of identified malicious software registry threats in the first half of 2026. Stardust Chollima used stolen maintainer credentials to compromise the Axios npm package in March. In June it injected a malicious npm dependency into at least 131 Mastra AI framework packages. The way in was a Mastra employee: the group approached them on LinkedIn, then got them onto a video call and talked them into clicking a malicious link. Internet crime group Altered Spider works at a different scale. Its malware self-propagates, taking stolen maintainer credentials and republishing infected packages on its own. In one day during its May campaigns, the group compromised more than 300 software dependencies. In March, it poisoned Git tags on the publicly available trivy-action GitHub Action, part of Aqua Security Software Ltd.’s Trivy scanner, so that any organization pulling the affected releases in an automated build ran credential-stealing malware inside its own pipeline. Researchers at Forcepoint LLC detailed that compromise in May and traced it to a group they called TeamPCP. CrowdStrike attributes the activity to Altered Spider. Identity abuse rounds out the picture. Vishing intrusions in the first half of 2026 ran at twice the rate of the second half of 2025, following a 134% increase between 2024 and 2025. Cordial Spider and Snarky Spider used vishing calls to steer targets to spoofed single sign-on pages loaded on personal mobile devices, then moved into integrated software-as-a-service applications to exfiltrate data. In one incident, Snarky Spider went from account takeover to data theft in under five minutes. Monthly device code phishing attempts rose 15-fold over the past six months. Cloud-conscious internet crime activity climbed 171% over the reporting period. In one case a threat actor hijacked cloud resources at a U.S. technology company across three parallel attack vectors, mining about $41,000 worth of Monero while altering instance settings to stop the victim reclaiming the compute. Not every intrusion arrived over a network. Between March and May, OverWatch disrupted close access operations in which China-nexus adversary Overcast Panda installed its FlowCloud backdoor on unattended laptops belonging to travelers inside China. The adversary booted the machines from removable media, writing the implant to disk outside the running operating system. Overall intrusion activity rose roughly 4%, well down on the 27% surge reported a year ago, though this year’s count includes automated attacks that earlier editions excluded. CrowdStrike attributed the plateau to adversaries putting time into fewer, more complex campaigns. Technology was the most targeted sector for the ninth consecutive year, while financial services and academic institutions recorded the largest increases, at 11% and 17%. “AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” said Adam Meyers, head of counter adversary operations at CrowdStrike, in announcing the report. “The organizations that succeed will secure AI as aggressively as they adopt it and use AI to defend at the speed of the adversary.” Photo: Robert Hof/SiliconANGLE A message from John Furrier, co-founder of SiliconANGLE: Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities. 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links. About SiliconANGLE Media SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
CrowdStrike finds AI systems under direct attack as exploit windows shrink
Full Article
Original Source
Read the full article at Siliconangle →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.