2026 Threat Hunting Report

2026-08-03 Crowd Strike

https://www.crowdstrike.com/en-us/resources/reports/threat-hunting-report

Attachments

source_3885.pdf (54 MB)

Thumbnail for 2026 Threat Hunting Report

CrowdStrike attributes the poisoning of 131 AI framework packages to the North Korea-linked STARDUST CHOLLIMA adversary, demonstrating an effort to compromise trusted components upstream in the developer ecosystem. Such poisoned dependencies can provide a launchpad for downstream and cross-domain compromise. The broader hunting data also shows adversaries accelerating exploitation with AI and abusing trusted identities, cloud services, and software supply chains.

Related Actors

Related Reports

« Back