Black Hat 2026: CrowdStrike Threat Hunting Report Findings 

CrowdStrike’s 2026 Threat Hunting Report highlights how AI, identity attacks, and software supply chain threats are reshaping cyber risk.

Written By
Ken Underhill
Ken Underhill
Aug 4, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Cyber adversaries are moving faster, exploiting trust instead of brute force, and increasingly combining automation with hands-on operations to evade traditional security controls. 

CrowdStrike released its 2026 Threat Hunting report alongside Black Hat 2026. 

Its findings show that threat actors are accelerating vulnerability exploitation, abusing artificial intelligence (AI), targeting software supply chains, and shifting toward identity and cloud-centric attacks. 

These evolving tactics are leaving organizations with increasingly limited time to detect and respond before attackers achieve their objectives. 

Key takeaways of CrowdStrike’s 2026 Threat Hunting report

  • AI-enabled cyber threats surged 89% as attackers accelerated exploitation and phishing.
  • 88% of observed vulnerability attacks began within 48 hours of public PoC release.
  • Vishing, OAuth abuse, and trusted identities are driving faster enterprise compromises.
  • Software supply chain attacks increasingly target developer tools and AI ecosystems.
  • Cloud-focused eCrime activity jumped 171% as attackers pursued credentials and financial assets.

How AI is reshaping cyberattacks and threat hunting 

One of the report’s central findings is that AI has simultaneously become a defensive capability, an attack surface, and a force multiplier for threat actors. 

CrowdStrike notes that AI-enabled adversary activity surged 89% during 2025, with attackers using AI to improve phishing campaigns, reconnaissance, exploit development, and operational efficiency. 

They also observed AI-generated detection leads occurring 2.5 times more frequently than human-generated leads, highlighting AI’s growing role in modern threat hunting.

The report also found that frontier AI is shrinking the timeline between vulnerability disclosure and active exploitation. 

From January through June 2026, CrowdStrike observed that 88% of attacks exploiting vulnerabilities with publicly available proof-of-concept (PoC) code began within 48 hours of its release. 

CrowdStrike expects AI-assisted vulnerability discovery to further shrink patch windows, increasing the need for continuous exposure management. 

Advertisement

Identity threats and vishing drive initial access attacks 

Rather than exploiting software vulnerabilities alone, many adversaries now focus on trusted identities, cloud authentication, and SaaS applications.

CrowdStrike reported a twofold increase in vishing intrusions during the first half of 2026 compared with the second half of 2025. 

Threat groups such as CORDIAL SPIDER and SNARKY SPIDER impersonated IT personnel to gain employees’ trust. 

They then convinced users to authenticate through adversary-in-the-middle (AiTM) phishing pages before quickly accessing Microsoft 365 and Google Workspace environments. 

In one observed incident, attackers progressed from account takeover to data exfiltration in less than five minutes.

The report also found a 15-fold increase in OAuth device code phishing as cybercriminals abused legitimate Microsoft authentication workflows to steal cloud access tokens. 

Software supply chain attacks target developer ecosystems 

Developer ecosystems remain one of the fastest-growing attack surfaces.

According to CrowdStrike, malicious npm packages accounted for 87% of observed malicious software registry activity during the first half of 2026. 

Instead of targeting individual organizations, adversaries increasingly compromise CI/CD pipelines, package repositories, and developer tools to reach thousands of downstream victims. 

The report identifies STARDUST CHOLLIMA and ALTERED SPIDER among the most active software supply chain threat actors. 

In one campaign, ALTERED SPIDER compromised more than 300 software dependencies in a single day while harvesting developer credentials that enabled follow-on cloud intrusions and ransomware activity.

CrowdStrike also notes that AI development environments are becoming attractive targets because they often contain cloud credentials, API keys, and other access to enterprise infrastructure. 

Advertisement

Cloud attacks drive credential theft and cryptomining 

The report describes a significant shift toward financially motivated cloud attacks.

Cloud-conscious eCrime activity increased 171% over the reporting period as threat actors pursued cryptomining, cloud resource hijacking, credential theft, and attacks against digital financial assets. 

Instead of exploiting perimeter weaknesses, attackers increasingly operate inside trusted cloud environments using valid credentials and authentication tokens.

CrowdStrike documented campaigns where attackers abused cloud APIs, harvested cloud credentials, and launched cryptomining operations that generated tens of thousands of dollars in unauthorized cloud costs. 

Because individual cloud API calls often appear legitimate, the report emphasizes that behavioral analytics across cloud control planes are becoming essential for identifying malicious activity.

Continuous threat hunting is essential for modern attacks 

Although overall intrusion activity increased by only about 4% year over year, which is a drop from last year’s 27%, CrowdStrike suggests this reflects a maturing threat landscape rather than reduced risk. 

Adversaries are launching increasingly sophisticated campaigns that combine automation with hands-on attacks across identity, cloud, AI, and software supply chains. 

Technology remained the most targeted industry for the ninth consecutive year, while financial services and academic organizations experienced some of the largest increases in intrusion activity.

To counter these trends, CrowdStrike recommends continuous, intelligence-driven threat hunting across endpoints, identities, cloud, SaaS, and developer environments. 

The report also recommends securing AI environments, strengthening identity and software supply chain security, reducing attack surfaces, and using proactive threat intelligence. 

Advertisement

As enterprise environments expand across cloud and AI, organizations can no longer rely solely on reactive security controls. 

Instead, defenders must combine behavioral monitoring, threat intelligence, and continuous threat hunting to detect adversaries abusing trusted identities and legitimate infrastructure.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.