Security firm CrowdStrike, in its 2026 Threat Hunting Report, assessed that AI is becoming a direct target beyond being an attack tool, and that the speed of vulnerability exploitation has accelerated to an hourly pace.
Attacks are spreading across AI infrastructure, access rights to corporate large language models, software supply chains and cloud resources, CrowdStrike said.
The report includes findings from tracking more than 290 named attack groups over the year from July 2025 to June 2026. CrowdStrike said it has included automated attacks in its tally from this year, in addition to intrusions carried out directly by humans.
The report said the speed of vulnerability exploitation is increasingly accelerating. CrowdStrike measured the interval from the release of a proof-of-concept exploit to its use in real attacks in hours, and said that from January to June this year, 88 percent of cases had an interval of less than 48 hours.
China-linked groups Volt Panda and Genesis Panda moved even faster. The unauthenticated remote code execution vulnerability in React Server Components and Next.js, dubbed React2Shell (CVE-2025-55182), was disclosed on Dec. 3, 2025, and working exploit code emerged the next day. The two groups launched attacks within 24 hours.
It also found indications of direct targeting of AI infrastructure.
An attack dubbed LLMjacking, which steals access rights to corporate large language models, has also emerged. Software repositories remained a key route for intrusions into developer environments. In the first half of 2026, 87 percent of malicious software repository threats identified were malicious npm packages.