Vishing intrusions have doubled, cloud attacks by financially motivated actors have surged 171%, and vulnerabilities are exploited within 48 hours of disclosure — CrowdStrike’s latest Threat Hunting Report reveals how adversaries are exploiting trust faster than defenders can respond.
Cybercriminals and state-sponsored groups are no longer forcing their way through front doors — they are walking through ones defenders leave open. According to CrowdStrike’s 2026 Threat Hunting Report, covering intrusion activity from July 2025 to June 2026, adversaries increasingly exploit valid credentials, cloud authentication flows, SaaS platforms, and software supply chains to gain undetected access, while artificial intelligence accelerates both their reconnaissance and their exploitation timelines.
The report, compiled by CrowdStrike OverWatch and CrowdStrike Intelligence, analyzes seven trillion daily telemetry events and documents more than 36,000 customer notifications issued over the past year. For the first time, the report’s scope was expanded beyond interactive, hands-on-keyboard intrusions to include automated attacks, reflecting what the company describes as a maturing threat landscape in which sophisticated actors blend scalable automation with traditional tradecraft.
Overall intrusion activity grew approximately 4% year-over-year — a marked slowdown compared to the 27% surge recorded the previous year. CrowdStrike attributes this plateau not to reduced adversary intent, but to a shift toward more complex, resource-intensive campaigns rather than opportunistic, high-volume attacks. Technology remained the most targeted sector for the ninth consecutive year, while financial services and academic institutions recorded the sharpest increases in targeting, at 11% and 17% respectively.
Vulnerabilities exploited within hours
According to the report, 88% of observed exploitation of vulnerabilities with a public proof-of-concept occurred within 48 hours of release between January and June 2026. China-nexus adversaries VAULT PANDA and GENESIS PANDA moved even faster, launching attacks within 24 hours of the critical React2Shell vulnerability’s disclosure in December 2025 — a campaign that generated more than 800 hunting leads at over 80 victim organizations in just four days. CrowdStrike expects frontier AI systems to further compress these windows as they increasingly assist vulnerability discovery.
Software supply chains under systematic attack
Supply chain compromises intensified sharply, with malicious npm packages accounting for 87% of all identified malicious software registry threats in the first half of 2026. The eCrime adversary ALTERED SPIDER compromised more than 300 software dependencies in a single day using self-propagating malware, while the North Korea-linked STARDUST CHOLLIMA infiltrated developer ecosystems through social engineering, including a case in which an employee was tricked via a fraudulent LinkedIn video call. CrowdStrike warns that AI development tooling — SDKs, model frameworks, and MCP integrations — is emerging as the next major supply chain battleground.
Vishing becomes a preferred entry point
Voice phishing has become one of the fastest-growing initial access vectors, with CrowdStrike OverWatch recording a doubling of vishing intrusions in the first half of 2026 compared to the second half of 2025. Adversaries such as CORDIAL SPIDER and SNARKY SPIDER impersonate IT staff to trick employees into authenticating on spoofed single sign-on pages, then rapidly exfiltrate data from SaaS applications — in one case, SNARKY SPIDER moved from account takeover to data theft in under five minutes.
Cloud environments as the new frontline
Financially motivated cloud-targeting activity rose 171% over the reporting period, driven by credential theft, cryptomining, and abuse of large language model access, known as LLMJacking. Device code phishing attempts increased fifteenfold in six months, as attackers exploit trusted OAuth 2.0 authentication flows to bypass multi-factor authentication entirely. In one documented case, a threat actor sent nearly 200,000 API requests to a cloud AI service within two minutes.
Physical access and close-proximity espionage
The China-nexus adversary OVERCAST PANDA employed an entirely different approach, physically compromising devices belonging to business travelers in China — often while victims were at dinner during conferences — by booting laptops from USB media to install the FlowCloud backdoor, bypassing network-based defenses entirely.
Recommendations
CrowdStrike urges organizations to treat AI systems, identity infrastructure, and developer environments as primary attack surfaces requiring continuous, intelligence-led monitoring rather than static controls, arguing that only behavioral, cross-domain threat hunting can keep pace with adversaries who now operate across endpoint, cloud, identity, and AI domains simultaneously.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de