Overview
- Citing CrowdStrike’s 2026 Threat Hunting Report published Monday, the firm found AI-enabled malicious activity rose 89% over the past year and AI-driven detection leads grew roughly 2 to 2.5 times.
- The report shows defenders face a flood of noisy signals because AI agents generate far more alerts than human-driven activity, making it harder to spot real intrusions quickly.
- CrowdStrike documented a compressed exploit timeline with 88% of detected exploits launched within 48 hours of a public proof-of-concept release, shrinking the window for patching and response.
- Attackers are abusing LLMs and open-source supply chains by using frontier models to write exploit code, stealing model credentials for LLMJacking campaigns that can trigger hundreds of thousands of API calls, and compromising hundreds of dependencies in single supply-chain operations.
- The company urges immediate operational fixes such as enforcing least-privilege on human and non-human accounts, protecting AI credentials, monitoring LLM usage and costs, and improving software supply-chain visibility to reduce rapid, AI-driven risk to organizations and users.