AI, cloud attacks, software supply chains, and vishing dominate the latest cyber threat trends in CrowdStrike's new report.
Threat actors are increasingly leveraging Large Language Models (LLMs) to enhance their attack capabilities, using them to generate sophisticated malware, craft convincing phishing emails, and devise efficient reconnaissance commands and scripts once they've compromised systems. This integration of AI significantly shortens the time between the public disclosure of a vulnerability and its active exploitation, enabling adversaries to quickly identify weaknesses, generate proof-of-concept (PoC) exploits, and launch attacks. The report highlights instances where attackers exploited AI server software to steal sensitive configuration data and install cryptocurrency miners. Additionally, financially motivated groups are abusing enterprise AI platforms in a new form of attack dubbed LLMJacking, which involves overwhelming a victim's AI resources. One notable incident saw attackers gaining administrative access to a cloud account and then submitting nearly 200,000 requests to LLMs within a mere two minutes, incurring substantial costs for the victim. The acceleration of exploitation is stark: between January and June 2026, 88% of observed exploitations of vulnerabilities with publicly available PoC code occurred within 48 hours of release, with some China-linked groups launching attacks even faster, within 24 hours.
Software supply chains are increasingly becoming a preferred vector for attacks, with adversaries hiding malicious code within seemingly legitimate software packages uploaded to public repositories frequently used by developers. Once installed, these compromised packages can distribute malicious code to thousands of downstream users, creating a wide-reaching impact. The npm package registry alone accounted for a staggering 87% of all malicious software packages identified during the reporting period, underscoring the scale of this problem. Threat actors are systematically compromising various components of the developer ecosystem, including package registries, Continuous Integration/Continuous Deployment (CI/CD) pipelines, container registries, and Integrated Development Environment (IDE) extensions. This approach is highly effective because these components provide direct access to critical systems such as production environments, sensitive cloud infrastructures, and extensive customer networks. Prominent groups involved in these attacks include the North Korea-linked STARDUST CHOLLIMA and the financially motivated ALTERED SPIDER. One campaign attributed to ALTERED SPIDER reportedly compromised over 300 software dependencies in a single day, allowing the group to steal credentials and gain unauthorized access to cloud environments.
Vishing, a form of social engineering that uses voice communication, has emerged as one of the fastest-growing methods for gaining initial access into target organizations. In these attacks, adversaries impersonate trusted figures, typically IT support staff, over the phone to manipulate employees. They persuade victims to either enter their credentials into fake login pages or approve remote access requests using legitimate software such as Microsoft Quick Assist. The effectiveness of vishing stems from its reliance on valid credentials provided by the victim, which often allows attackers to bypass traditional security tools that might detect other forms of intrusion. The report indicates a significant surge in vishing-related intrusions, which increased by 134% between 2024 and 2025. This activity further accelerated during the first half of 2026, with twice as many incidents observed compared to the preceding six months. Specific threat groups like CORDIAL SPIDER and SNARKY SPIDER have effectively utilized vishing to compromise single sign-on (SSO) accounts, subsequently gaining access to critical enterprise environments such as Microsoft 365 and Google Workspace. In one particularly rapid SNARKY SPIDER intrusion, attackers escalated from an account takeover to full data theft in less than five minutes.
Cloud-focused cybercrime activity has seen a dramatic increase, spiking by 171% over the past year. This surge is primarily driven by various malicious objectives, including credential theft, the illicit deployment of cryptocurrency miners, abuse of AI services, and attempts to steal valuable digital assets. One of the fastest-growing techniques in this domain is device code phishing, an ingenious method that exploits legitimate authentication processes, particularly those used by Microsoft. Attackers trick users into unknowingly authorizing malicious logins through trusted authentication workflows, making it difficult for users to distinguish between legitimate and fraudulent requests. Device code phishing attempts have alarmingly increased 15-fold during the past six months, highlighting its growing prevalence and effectiveness. Adversaries are actively targeting a range of sensitive cloud assets, including cloud credentials, API keys, and other secrets stored within cloud services, to gain unauthorized access to cryptocurrency wallets and other high-value digital assets. The detection of these intrusions often presents a significant challenge for security teams, as attackers frequently rely on compromised but otherwise legitimate accounts and authentication tokens, making their activities appear less suspicious.
For the ninth consecutive year, the technology sector has maintained its position as the most targeted industry by cybercriminals. This sustained focus is due to several factors: technology companies possess vast amounts of valuable intellectual property, and they often serve as crucial entry points for broader software supply chain compromises, affecting numerous downstream clients. Beyond technology, the financial services sector experienced an 11% increase in intrusion activity during the reporting period. Financial institutions remain highly attractive targets for attackers seeking direct financial assets, banking credentials, and sensitive customer data. Universities and research institutions also faced a significant escalation in attacks, with a 17% increase, marking the largest rise among all sectors. Academic organizations are increasingly targeted for their cutting-edge research, intellectual property, and often less robust security infrastructures compared to large corporations, making them lucrative targets for espionage and data theft.