CrowdStrike’s 2026 Threat Hunting Report finds that artificial intelligence has become deeply embedded in cyberattack operations, serving as both a tool for attackers and a target of exploitation. The report documents that North Korean-nexus groups compromised 131 trusted AI framework packages, while eCrime actors abused enterprise AI systems for credential theft and cryptomining. Exploitation windows have collapsed sharply, with 88% of observed vulnerability exploits occurring within 48 hours of a public proof-of-concept release, and China-nexus adversaries exploiting some critical vulnerabilities within 24 hours of disclosure.