AI Security - 7 min read - 5 August 2026

CrowdStrike watched attackers weaponise a public exploit in 20 hours. Your patch cycle wasn't built for that clock.

CrowdStrike's 2026 Threat Hunting Report, published 3 August from a year of front-line intrusion data, puts a hard number on something most security teams have felt anecdotally for a while: 88% of vulnerabilities exploited between January and June had a public proof-of-concept in circulation for 48 hours or less before someone used it. One tracked group moved in 20. The report's second finding is the more uncomfortable one - AI isn't only accelerating that clock, it's now a target of its own, with a DPRK-linked actor poisoning 131 trusted AI framework packages to get there.

CrowdStrike's threat hunters sit inside customer environments watching intrusions unfold in real time, which is what gives this report its texture: it isn't survey data, it's what happened. According to CrowdStrike's own summary of the findings, covering July 2025 through June 2026, 88% of attacks exploiting a vulnerability with a public proof-of-concept began within 48 hours of that code becoming available. Two named groups, tracked as VAULT PANDA and GENESIS PANDA, moved on a critical web application flaw within 24 hours of disclosure. A third, UMBRAL BISON, weaponised CVE-2026-31431 in 20 hours flat, with 94% of the resulting exploitation activity landing in that first day. eSecurity Planet's independent coverage of the Black Hat presentation frames the shift plainly: the industry's old assumption that a CVE disclosure buys defenders a few days' grace before mass exploitation no longer holds for anything with usable proof-of-concept code attached.

The 48-hour number is a patch-SLA problem, not a headline

Most vulnerability management programmes are still built around monthly or fortnightly patch cycles, with "critical" severity buying a shortened window measured in days rather than hours. A 48-hour median time-to-exploitation - and 20 hours for the fastest observed group - makes that cadence structurally too slow for the specific subset of vulnerabilities that ship with public exploit code. The React2Shell vulnerability is the case study CrowdStrike uses to show the blast radius that speed produces: CrowdStrike's press release notes over 800 separate hunting leads across more than 80 victim organisations inside four days of disclosure. That isn't a slow trickle of opportunistic scanning - it's a coordinated sweep executed faster than most change advisory boards can convene.

AI as target, not just tool

The report's AI findings cut two ways. On the offensive side, CrowdStrike says AI-enabled adversary activity grew 89% year over year, used mainly to speed up phishing content, reconnaissance and exploit development rather than to invent wholly new attack techniques - AI as force multiplier for known playbooks. The sharper finding is the defensive mirror image: AI systems themselves are now a named target category. One LLMJacking campaign generated close to 200,000 API requests in two minutes against a compromised AI service, run up specifically to burn through someone else's model access and compute budget. Separately, the DPRK-linked group FAMOUS CHOLLIMA used AI-themed lures and fake AI tooling to compromise cryptocurrency and blockchain firms - AI as the bait, not the weapon, in that case.

131 poisoned packages is the number that should reach your AI platform team

The supply chain findings tie the AI and software-registry threads together directly. CrowdStrike attributes to STARDUST CHOLLIMA, a DPRK-nexus actor, the injection of malicious code into at least 131 trusted packages within the Mastra AI framework ecosystem in June 2026 - a scale that turns "check your dependencies" from routine hygiene into an active AI supply chain risk. Across all software registries, CrowdStrike found 87% of identified registry threats in the first half of 2026 involved malicious npm packages, and a separate eCrime actor, ALTERED SPIDER, compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments. None of this requires a novel technique - it's the same dependency-poisoning playbook long documented in the broader npm ecosystem, now aimed deliberately at the packages AI teams pull in without a second thought because "it's just a framework."

We've covered adjacent ground on this before - the Ruflo MCP bridge flaw that let attackers poison an AI agent's own memory store, and the Hugging Face agentic AI breach that moved through a compromised inference pipeline. CrowdStrike's report is the aggregate view behind those individual incidents: AI infrastructure is now a first-class target category with its own supply chain, and the same actors treating exploit speed as a competitive advantage against traditional CVEs are applying identical patience and scale to AI package ecosystems that most organisations still treat as lower-risk than their core application stack.

  • Re-examine your patch SLA for anything CISA has flagged with confirmed or likely public proof-of-concept code - 48 hours, not weeks, is the operative exploitation window CrowdStrike observed this year.
  • Build an emergency patch path that can move in under 24 hours for actively-exploited, internet-facing flaws, separate from your standard change process.
  • Extend software composition analysis and registry monitoring specifically to AI framework dependencies (Mastra and equivalents), not just general-purpose npm packages.
  • Treat AI service accounts and API keys as a distinct monitoring category - the LLMJacking pattern CrowdStrike describes is detectable through unusual request-volume spikes, not traditional endpoint telemetry.
  • Ask any AI platform or agent vendor directly what package-provenance and signing controls sit in front of their framework's dependency tree.

The gap CrowdStrike's data actually measures isn't a technology gap - it's the difference between how fast attackers now move and how fast most patch and procurement processes are built to respond. If you'd like help closing that gap, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources