Learn how adversaries weaponize trust across domains
- AI systems have become high-value attack targets
- Vulnerabilities are being exploited hours after disclosure
- Identity abuse turns trusted logins into cloud access
Threat actors use AI to generate payloads and shell commands, exploit AI infrastructure, and abuse enterprise LLMs
200K API requests sent in two minutes during an LLMJacking campaign, exploiting the victim’s AI resources at scale
The same AI tools driving modern businesses are creating underdefended attack surfaces that adversaries are already exploiting
China-nexus adversaries exploit vulnerabilities after effective PoC disclosure
victims identified in just four days after React2Shell vulnerability disclosure
software dependencies compromised in a single day by ALTERED SPIDER
AI framework packages poisoned by STARDUST CHOLLIMA
surge in eCrime cloud-conscious activity
spike in monthly device code phishing attempts
Explore the Adversary Hub to learn how the world’s most dangerous threat actors are targeting organizations like yours.
Small and Medium-Sized Businesses (SMBs):
SMBs often lack the resources to build comprehensive in-house security operations. Threat intelligence helps them achieve a level of protection they otherwise couldn't afford, offering insights that allow them to prioritize defenses and mitigate risk.
Enterprises:
For larger organizations with dedicated security teams, threat intelligence reduces costs, minimizes the required skill set for incident handling, and enhances the effectiveness of security analysts by integrating external data into their operations.
Methodology & Source: All information provided is based on the CrowdStrike Counter Adversary Operations team’s proprietary threat intelligence gathered between July 1, 2025, and June 30, 2026. Stats may include data from the entire period surveyed or excerpts of data from specific date ranges within the period.