The 30-Day Patch Cycle Is Dead
CrowdStrike's 2026 Threat Hunting Report, published August 3, puts a hard number on something security teams have felt anecdotally for years, that the gap between vulnerability disclosure and active exploitation has collapsed to almost nothing. The report found that 88 percent of vulnerabilities with publicly available proof-of-concept exploit code were weaponized within 48 hours of disclosure. That figure represents the overwhelming majority of cases landing inside a two-day window, leaving almost no room for the deliberative change-management cycles most enterprise patch programs were built around a decade ago.
China-nexus threat actors were the fastest movers CrowdStrike tracked, launching attacks against newly disclosed flaws within 24 hours in multiple documented cases. Adam Meyers, CrowdStrike's head of counter adversary operations, framed the shift plainly: AI is now embedded in modern adversary operations, and organizations that succeed will secure AI as aggressively as they adopt it. For patch management programs still built around monthly or even weekly cycles, that framing is a direct challenge to the operating model, not a suggestion.
AI as the Attacker's Force Multiplier
The report documents AI-enabled malicious activity increasing 89 percent over the past year, driven largely by attackers using frontier models to accelerate vulnerability discovery, exploit development, and payload generation. One campaign CrowdStrike tracked sent nearly 200,000 AI model requests in a two-minute window, automation at a scale no human-operated attack could plausibly replicate working manually. This automation is what compresses the disclosure-to-exploitation timeline so dramatically, since the labor-intensive work of writing functional exploit code, previously a bottleneck that bought defenders days or weeks to patch, has become substantially automated on the attacker side of the equation.
The software supply chain shows the same pattern playing out in a different attack surface. Malicious npm packages accounted for 87 percent of software registry threats CrowdStrike tracked in the first half of 2026, and one eCrime actor compromised more than 300 software dependencies in a single day, an operational tempo that again points to automated tooling rather than manual package-by-package compromise. North Korea-nexus adversaries went further, compromising 131 trusted AI framework packages specifically, deliberately targeting the tooling that enterprise AI teams increasingly depend on to build, fine-tune, and deploy their own models into production.
AI as the Target, Not Just the Tool
CrowdStrike's report frames AI as simultaneously a weapon and a target, and the second half of that framing deserves equal attention from enterprise security teams planning their own AI rollouts. As organizations stand up agentic systems and integrate AI applications into core workflows, those systems become their own attack surface, with adversaries probing agent-to-agent communication, model integrations, and AI infrastructure the same way they once probed web applications and APIs a decade earlier.
Meyers was direct about the implication, stating that AI agent-driven behaviors have surged past human triggers inside the environments CrowdStrike monitors, making AI a tool, a target, and a force multiplier for adversaries all at once. His conclusion for defenders followed the same logic: organizations have to secure AI, a step he called absolutely critical rather than a future roadmap item. Security programs that have deployed AI tooling without a corresponding AI-specific threat model are operating with a blind spot the report suggests adversaries are already actively probing for weaknesses.
The Volume Problem for Defenders
The defensive side of the ledger shows the scale security operations centers are now working against. CrowdStrike triages 14 million detection leads daily, resulting in roughly 36,000 customer alerts over the course of a year, and AI agent-triggered detection leads are growing at 2.5 times the rate of human-triggered leads. That ratio functions as a leading indicator, because as adversaries automate more of their tradecraft with AI, the volume of signal defenders must sort through grows faster than headcount or traditional SOC tooling can realistically scale to match.
CrowdStrike now tracks more than 290 named adversaries, a roster that keeps expanding as AI lowers the technical barrier for new groups to develop working capabilities without the years of tradecraft development that used to be required. For CISOs, this data makes the practical argument for AI-assisted detection and triage rather than a strategic nice-to-have buried in next year's budget request, since the volume of AI-generated attacker activity is already outpacing what human analysts alone can process within the time windows that now matter most.
Old Tricks Are Making a Comeback Too
Not every trend in the report concerns novel AI tradecraft. Vishing, voice phishing conducted over phone calls, doubled in intrusion volume during the first half of 2026, and device code phishing attempts, which trick users into authorizing a malicious login flow, increased fifteenfold over the same period. Cloud-conscious eCrime activity, attacks specifically designed to operate within and abuse cloud infrastructure once an attacker has a foothold, surged 171 percent across the environments CrowdStrike monitored during the same window.
The resurgence of low-tech social engineering alongside high-tech AI-driven exploitation tells a consistent story about how attackers actually operate day to day: they gravitate toward whichever method produces results fastest, and they run AI-driven and human-manipulation tactics simultaneously rather than picking one approach over the other. Security awareness training programs that have not been refreshed to cover vishing and device code phishing specifically are falling behind a threat landscape that CrowdStrike's data shows is actively reviving these older techniques at meaningful scale.


