AI has remade the cyber threat landscape over the past year — on both sides of the fight. CrowdStrike's 2026 Threat Hunting Report, released August 3, puts the rise in AI-enabled adversary activity at 89 percent year over year, painting a picture of a battlefield in which machines are both the weapons and the targets.

Among the most striking findings: STARDUST CHOLLIMA, a North Korean operator, injected malicious code into 131 packages of the trusted Mastra AI framework library. China-nexus groups are exploiting critical vulnerabilities within 24 hours of a public proof-of-concept's release; eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day; and one campaign fired nearly 200,000 AI model requests in two minutes.

The report also documents a 171 percent surge in cloud-conscious attacks targeting LLM abuse and credential theft. Average breakout time — the window an attacker needs to move laterally through a network — keeps shrinking as AI automates stages of the attack chain that once required manual skill.

CrowdStrike's conclusion is blunt: defenders must now deploy AI of their own just to keep pace, and supply-chain attacks on open-source AI have become a preferred tactic for state actors. The report's message is that the era of rare AI-powered intrusions is over — and the open software infrastructure the AI industry is built on has become its most exposed front.