started · updated
CrowdStrike report: AI fuels rapid surge in global cyberattacks
CrowdStrike’s ‘2026 Threat Hunting Report’ reveals that artificial intelligence has become both a primary tool and a major target for global cyberattacks. The report highlights a rapid shift in the threat landscape, where AI is being used to automate and scale attacks, including the generation of payloads and shell commands.
Key findings indicate that Chinese-linked groups, such as ‘Vault Panda’ and ‘Genesis Panda’, are exploiting software vulnerabilities in less than 24 hours after they are disclosed. Additionally, North Korean-linked actors, specifically ‘Stardust Chollima’, have targeted the AI ecosystem by injecting malicious npm packages into 131 ‘Mastra’ AI framework instances.
Cloud-targeted cybercrime has surged by 171% year-over-year. Attackers are increasingly focusing on AI infrastructure, software supply chains, and Large Language Models (LLMs). The report also notes a significant rise in phishing attempts, with device code phishing increasing 15-fold and voice phishing doubling, as criminals exploit trusted authentication workflows.
Entities
Altered Spider · CrowdStrike · Genesis Panda · Stardust Chollima · Vault Panda