CrowdStrike’s 2026 Threat Hunting Report finds artificial intelligence systems are now being directly targeted, with attacks on AI infrastructure, model access and large language model services joining a broader surge in automated intrusions. The report says attackers adopt exploits within hours of disclosure, with most proof-of-concept code weaponized in under two days. China-linked and other groups rapidly abused React2Shell, npm packages, GitHub actions and cloud resources using stolen identities. CrowdStrike concludes adversaries are both using and attacking AI, favoring fewer, more complex campaigns. Technology, financial services and academia face rising pressure, with recommended responses including securing AI infrastructure and applying AI-driven detection at comparable speed.
This update represents a notable development in the Ai sector. Organizations and founders tracking this space should evaluate potential strategic and technical implications on their operations.