CrowdStrike's 2026 Threat Hunting Report highlights how cybercriminals are weaponizing AI while simultaneously exploiting vulnerabilities in corporate AI deployments.
Key facts
- •CrowdStrike reports 2.5 times more AI-triggered leads than manual leads, complicating threat detection.
- •The 'Famous Chollima' group uses AI-generated content and deepfakes to target cryptocurrency and blockchain firms.
- •88% of exploits detected in the first half of 2026 were launched within 48 hours of public proof-of-concept release.
- •LLMJacking allows attackers to steal data and force models to perform high-compute tasks at the victim's expense.
- •CrowdStrike recommends that companies monitor for suspicious LLM usage and enforce strict identity verification.
CrowdStrike's 2026 Threat Hunting Report, released Monday, warns that businesses are increasingly vulnerable as AI becomes both a tool for cybercriminals and a primary target. Researchers found that threat actors are adopting AI at the same speed as enterprises, creating massive volumes of attack signals that outpace manual defense. This shift is forcing organizations to rethink security as AI-driven attacks become faster and more difficult to distinguish from legitimate traffic.
By the numbers
AI as a Weapon and Attack Surface
Cybercriminals are using AI to generate phishing and vishing materials, payloads, and commands to streamline attacks. A significant threat identified is 'LLMJacking,' where attackers steal credentials to access a company's cloud-based AI models. In one documented instance, an attacker forced a victim's LLM to perform nearly 200,000 API requests in just two minutes, causing significant operational and financial damage. Additionally, groups like the DPRK-associated 'Famous Chollima' are using AI-generated resumes and deepfake interviews to infiltrate organizations in the cryptocurrency and blockchain sectors.
Compressed Response Timelines
The report highlights a shrinking window for defenders to respond to vulnerabilities. Between January and June 2026, 88% of exploits detected by CrowdStrike occurred within 48 hours of a public proof-of-concept code release. Some groups, such as China's Vault Panda and Genesis Panda, have developed exploits for critical vulnerabilities within a single day of disclosure. CrowdStrike notes that AI-assisted research is accelerating both vulnerability discovery and exploit development, putting immense pressure on human security teams.
Recommendations for Enterprises
To mitigate these risks, CrowdStrike advises companies to enforce least-privilege principles and protect AI-related credentials. Organizations are encouraged to implement phishing-resistant multifactor authentication and monitor for unusual LLM usage or cost spikes. The report also emphasizes the need for a proactive security stance, including better telemetry, frequent patching, and addressing cross-domain blind spots in the software supply chain.
Advertisement
This article was independently rewritten by ManyPress editorial AI from reporting originally published by ZDNET AI.
