---
schema: 1
kind: annual-report
title: "CrowdStrike 2026 Threat Hunting Report: 88% of public-PoC exploitation landed inside 48 hours, and npm accounted for 87% of software-registry threats"
headline: "OverWatch telemetry puts a number on the collapsing patch window — and nation-state actors beat 24 hours on a web-application flaw"
summary: >
  CrowdStrike Counter Adversary Operations published its 2026 Threat Hunting Report on 2026-08-03, covering the 12
  months to 30 June 2026. The load-bearing figure for patch prioritisation, measured over January to June 2026: 88% of
  observed exploitation of vulnerabilities carrying a public proof-of-concept happened within 48 hours of that PoC's
  release, with China-nexus VAULT PANDA and GENESIS PANDA attacking a critical web-application flaw inside 24 hours of
  disclosure and Belarus-nexus UMBRAL BISON exploiting a Linux privilege-escalation flaw just over 20 hours after it
  went public. The report also puts npm at 87% of identified software-registry threats in the same half-year, and finds
  vishing intrusions doubling against the preceding six months.
discovered_at: "2026-08-04T04:50:00Z"
event_date: "2026-08-03"
run_id: 2026-08-04T0411Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, actively-exploited, supply-chain, phishing, identity, ai-abuse, nation-state]
regions: [global]
sectors: [public-sector, technology, finance]
entities: [report:crowdstrike-threat-hunting-2026, actor:vault-panda, actor:genesis-panda, actor:umbral-bison, actor:altered-spider, actor:sapphire-sleet]
techniques: [T1190, T1566.004, T1195.002, T1078.004]
affected_products: []
cves: []
sources:
  - url: "https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/"
    publisher: "CrowdStrike Counter Adversary Operations"
    date: "2026-08-03"
    role: primary
  - url: "https://siliconangle.com/2026/08/03/crowdstrike-finds-ai-systems-direct-attack-exploit-windows-shrink/"
    publisher: "SiliconANGLE"
    date: "2026-08-03"
    role: corroborating
closed_sources: []
evidence:
  - quote: "From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC’s release."
    publisher: "CrowdStrike Counter Adversary Operations"
  - quote: "They uncovered Belarus-nexus activity in just over 20 hours after public disclosure."
    publisher: "CrowdStrike Counter Adversary Operations"
  - quote: "87% of identified software registry threats in the first half of 2026 involved npm packages."
    publisher: "CrowdStrike Counter Adversary Operations"
verification: multi-source
sourcing_note: >
  Figures are CrowdStrike's own OverWatch and Intelligence telemetry, not independently reproducible; SiliconANGLE
  corroborates the publication and its headline findings but is a second publisher rather than a second assessor, which is
  why credibility is 2 rather than 1. The Linux privilege-escalation flaw CrowdStrike names is CVE-2026-31431, already
  covered by this pipeline in May 2026; it is referenced here only as an exploitation-velocity data point and this run
  holds no advisory-grade record for it, so it is not carried in `cves[]`.
confidence: high
update_of: null
references: [2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal, 2026-05-09/cve-2026-31431-copy-fail-cisa-kev-deadline-2026-05-15-approa]
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions: []
migrated_from: null
---

CrowdStrike's Counter Adversary Operations team published its annual Threat Hunting Report on 2026-08-03, drawing on OverWatch managed-hunting and CrowdStrike Intelligence telemetry from what it describes only as "the past year" ([CrowdStrike, 2026-08-03](https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report/)); reporting on the release puts that window at the 12 months to 30 June 2026 ([SiliconANGLE, 2026-08-03](https://siliconangle.com/2026/08/03/crowdstrike-finds-ai-systems-direct-attack-exploit-windows-shrink/)). Only a few of its findings change a defender's decisions; those are the ones worth carrying.

The one that does most work is the exploitation-velocity measurement: "From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC's release." The named cases go faster still. China-nexus VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of the public disclosure of a critical web-application flaw, and after the React2Shell disclosure OverWatch worked 800+ hunting leads across more than 80 victims in four days. For a Linux local privilege-escalation flaw disclosed on 29 April with a researcher PoC released the same day, OverWatch saw widespread exploit deployment the following day — roughly 94% of first-day events matching public PoC testing behaviour — and for the Belarus-nexus actor UMBRAL BISON, "They uncovered Belarus-nexus activity in just over 20 hours after public disclosure." CrowdStrike's own read is that this pattern predates frontier AI models but that those models are likely to compress the timeline further by accelerating vulnerability discovery and exploit development.

The practical consequence is a prioritisation input rather than a task: for an internet-reachable component, the arrival of a public proof-of-concept is the trigger, and waiting for a KEV listing or the next scheduled maintenance window puts the decision after the exploitation rather than before it. That reframing bites hardest on the exposure classes this constituency runs at the perimeter — the edge appliances, management planes and web applications that need no user interaction to reach.

On the software supply chain, the concentration figure is the useful one: "87% of identified software registry threats in the first half of 2026 involved npm packages", which CrowdStrike attributes to JavaScript's dependency-chain scale and automatic install scripts. The named activity adds tradecraft detail on a cluster this store already tracks under the name Sapphire Sleet, one of whose recorded aliases is CrowdStrike's STARDUST CHOLLIMA: the DPRK-nexus actor used stolen maintainer credentials in March 2026 to compromise the axios npm package and deliver platform-specific variants of its ZshBucket malware, and in June 2026 injected a malicious npm package as a dependency into at least 131 Mastra AI framework packages — which CrowdStrike reads as trusted AI building blocks becoming supply-chain targets. A separate financially motivated actor, ALTERED SPIDER, compromised more than 300 software dependencies in one day, harvested credentials and pivoted into cloud environments.

Three identity and AI observations complete the picture without carrying separate action, because the underlying tradecraft is already covered in this store's operational entries. Vishing intrusions in H1 2026 doubled against H2 2025, with CrowdStrike recording one case in which an eCrime operator moved from account takeover to SaaS data theft in under five minutes. Monthly device-code phishing attempts rose 15x over six months. And on the defender's side of the ledger, "AI agent-triggered detection leads now surface 2.5x more threat leads than manually driven activity", which CrowdStrike frames as making it harder to separate malicious activity from expected AI-driven behaviour — a triage-volume problem rather than an attacker capability gain. One LLMjacking campaign generated nearly 200,000 API requests in two minutes against a hijacked service.

**Defender takeaway:** treat the 88%-within-48-hours figure as the justification for a standing decision most organisations have not yet formalised — that a public proof-of-concept against an internet-facing component starts a same-week clock regardless of KEV status, vendor severity or whether exploitation has been reported. Everything else here confirms directions this store already tracks (npm as the supply-chain centre of gravity, helpdesk vishing into single sign-on, device-code phishing) rather than opening new ground, and the per-incident detail for those lives in the referenced entries.
