The vendor's 2026 Global Threat Report tallies 89% more AI enabled adversary activity and an 88% rate of vulnerabilities weaponized through AI within 48 hours of disclosure.
CrowdStrike's 2026 Global Threat Report puts AI on both sides of 2025's attack cycle. The vendor's telemetry, covering roughly 280 named adversaries, showed AI-enabled activity up 89% year-over-year. Eighty-eight percent of vulnerabilities were weaponized through AI within 48 hours of disclosure, a figure Adam Meyers, CrowdStrike's SVP of counter adversary operations, called "one of the scarier stats" in the report coverage from The Register.
The 48-hour window has replaced the old 30-day patch cycle, Meyers said. CrowdStrike flagged FANCY BEAR's LLM-enabled LAMEHUG malware, used to automate reconnaissance and document collection, and DPRK-linked FAMOUS CHOLLIMA's full fake companies, built with AI-generated websites, GitHub accounts, and email infrastructure for insider operations, as the most advanced AI usage of the period. DPRK-nexus incidents rose 130%+ year-over-year.
On the defender side, agent-driven detection leads ran 2.5x the rate of human-triggered leads across roughly 14 million daily detection events, with about 36,000 customer alerts over the year. China-nexus activity rose 38%, state-nexus cloud targeting climbed 266%, and PRESSURE CHOLLIMA's $1.46 billion crypto theft was the largest single financial heist CrowdStrike logged, per CyberScoop's report on the same data.
The numbers are CrowdStrike's view of 2025, not an independent benchmark, and the vendor's commercial interest is plain. Average eCrime breakout time fell to 29 minutes, a 65% drop from 2024, with the fastest observed intrusion at 27 seconds and one exfiltration within four minutes of initial access.