CrowdStrike Threat Research
crowdstrike · B · active
https://www.crowdstrike.com/blog/category/counter-adversary-operations/
Falcon Counter Adversary Operations / Falcon Intelligence threat reporting. URL CORRECTED 2026-05-08: legacy /blog/category/threat-intel-research/ now 301-redirects to /en-us/blog/category.counter-adversary-operations/ — using the redirected URL avoids an unnecessary hop. 2026-05-08 audit: WebFetch returned 5 dated posts latest 2026-05-06 on OverWatch, CORDIAL/SNARKY SPIDER. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.crowdstrike.com/blog/category/counter-adversary-operations/ (listing, dates inline) then webfetch each /en-us/blog/<slug>/ article. AVOID: Do NOT use /en-us/blog/category/counter-adversary-operations/ — that variant 404s. The stored /blog/category/... URL is the correct listing; individual article URLs DO carry the /en-us/ prefix.. | 2026-07-05 admiralty audit: B — vendor threat-intel lab, original adversary research from own telemetry; live and drillable, no change (active).
Cited in 6 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 6).
- CrowdStrike 2026 Threat Hunting Report: 88% of public-PoC exploitation landed inside 48 hours, and npm accounted for 87% of software-registry threats2026-08-04
- npm / AI-developer-toolchain supply-chain wave status: this week the front edge moved from poisoning packages to poisoning the AI coding assistant's own trust config, via rogue MCP tool-provider entries2026-07-26
- SANDWORM_MODE — an npm supply-chain worm that 'lives off the AI toolchain', poisoning MCP servers in AI coding assistants to steal developer credentials2026-07-23
- CrowdStrike 2026 Technology Threat Landscape Report — "technology = most-targeted" reads as prophecy against this week's incidents2026-06-14
- CrowdStrike 2026 Technology Threat Landscape Report: technology is now the most-targeted sector2026-06-11
- CrowdStrike, Google and Shadowserver simultaneously sever all four C2 channels of the GlassWorm developer-targeting botnet (not to be confused with the Nx Console / TanStack GitHub-publish chain in § 5) — Russia-attributed, active since early 20252026-05-28