Cybersecurity

Hackers Now Exploit Software Flaws Within 24 Hours — and AI Is Making Their Job Easier

CrowdStrike's 2026 Threat Hunting Report puts a precise number on a trend security professionals have long suspected: 88
Susan Hill

The window between a vulnerability going public and the first real-world attack has almost disappeared. CrowdStrike’s 2026 Threat Hunting Report, covering the first half of the year, found that 88 percent of CVEs with published proof-of-concept exploits were used in active attacks within 48 hours. China-linked threat groups, including VAULT PANDA and GENESIS PANDA, have reached 24-hour turnaround on critical web application vulnerabilities — faster than most corporate IT teams can assess, let alone patch.

The React2Shell vulnerability, discovered earlier this year, generated 800 investigation leads and confirmed breaches at more than 80 victim organizations within four days of disclosure. A separate China-linked group, UMBRAL BISON, began exploitation of CVE-2026-31431 within 20 hours; 94 percent of related attack events were logged within the first day. These aren’t isolated cases — they represent what has become the standard operating pace for state-sponsored hacking.

Artificial intelligence is accelerating this further, though not yet in the science-fiction sense. The most measurable AI-related threat shift is on both sides of the attack chain: AI-agent-triggered security detections now produce 2.5 times more threat leads than manually driven activity, but the same automation is being turned against organizations. In one documented LLMJacking campaign — where attackers steal AI API credentials and run them for profit — a single operation generated 200,000 API requests in two minutes, scaling compute theft to a pace impossible without automation.

North Korea’s STARDUST CHOLLIMA moved from espionage into software supply chains in June: 131 packages in the Mastra AI development framework, widely used by developers building AI-powered applications, were injected with a malicious npm dependency. The campaign reflects a calculated bet that AI tooling — with its rapid adoption and often-slim security review — offers a high-yield poisoning surface. A separate group, ALTERED SPIDER, compromised more than 300 software dependencies in a single day.

Social engineering is keeping pace. Voice phishing — where attackers impersonate IT support or executives over phone calls — doubled in H1 2026 versus the previous six months. The group CrowdStrike tracks as SNARKY SPIDER moved from account takeover to confirmed data theft in under five minutes in documented incidents. Monthly device code phishing attempts have jumped 15-fold over the past six months, a technique that exploits the OAuth flows used to authenticate apps on smart TVs and limited-input devices.

The practical implication for anyone who uses software — not just security professionals — is that the effective patch window is now measured in hours. Enterprise security teams that relied on traditional 30-day vulnerability management cycles are running a race they’ve already lost. Cloud-based eCrime increased 171 percent year-over-year, a figure CrowdStrike attributes partly to the availability of commodity AI tools that lower the barrier for criminal actors who lack deep technical expertise.

CrowdStrike now tracks 290 named adversary groups, up substantially from prior years. The report notes that threat actor identification has itself become a bottleneck: the speed of modern campaigns often outpaces the attribution work needed to understand what you’re defending against. The numbers in the 2026 report don’t describe a future threat — they describe what is already being measured, every day, across thousands of organizations.

Tags: , , , , ,

Discussion

There are 0 comments.