AI Agents Now Trigger Risky Endpoint Behavior At 2.5 Times The Rate Of People

CrowdStrike’s 2026 Threat Hunting Report also documents adversaries exploiting a public proof-of-concept within a day, and CVE volume up 62% year on year.

Published on Aug 4, 2026
AI Agents Now Trigger Risky Endpoint Behavior At 2.5 Times The Rate Of People

AI agents have overtaken people as the leading source of risky behavior on corporate endpoints, according to CrowdStrike’s 2026 Threat Hunting Report.

In the first quarter of 2026, the company’s Falcon Adversary OverWatch team recorded agent-triggered detection leads at 2.5 times the rate of human-triggered ones.

Credit: Crowdstrike.

The figure comes from a hunting operation that analyzed around seven trillion events a day across endpoint, identity, cloud, and SIEM telemetry, and produced 36,000 customer notifications over the year.

CrowdStrike framed AI itself as a high-value target, rather than just a tool. It listed adversaries compromising AI developer accounts to reach downstream victims, manipulating AI data and systems directly, and hijacking AI resources so the victim absorbs the compute bill.

Exploitation Windows Are Collapsing

Two timelines in the report show how little room defenders now have.

React2Shell was disclosed by security researchers on December 3, 2025, with the first confirmed exploitation a day later.

Within roughly a day of that, CrowdStrike had observed two separate China-nexus groups, GENESIS PANDA and VAULT PANDA, using it. Inside four days of disclosure the team worked more than 800 hunting leads across more than 80 victims.

A second timeline shows the same compression outside China-nexus activity. An industry source released a CopyFail exploit on April 29, 2026, and the following day UMBRAL BISON was observed using it against a Ukrainian government entity.

The volume underneath is also growing. CrowdStrike counted 48,000 CVEs published in 2025, a 20% Year-on-Year (YoY) rise, and 43,000 so far in 2026, up 62%. June 2026 alone accounted for 7,400, a 96% increase on the same month last year.

Developer Tooling Is the Target

The report positions developer ecosystems, CI/CD pipelines, container registries, and IDE extensions as the current focus for supply chain attacks, with stolen privileged credentials used to pivot into cloud environments.

In the first half of 2026, 87% of malicious software registry threats involved npm packages, and CrowdStrike recorded ALTERED SPIDER compromising more than 300 software dependencies in a single day.

Elsewhere, vishing intrusions doubled in the first half of 2026 compared with the second half of 2025, with under five minutes elapsing between account takeover and data exfiltration in observed cases. CrowdStrike marked technology as the most targeted sector for nine consecutive years, while academia saw the largest overall increase at 17%.

Credit: Crowdstrike

CrowdStrike said it now tracks more than 290 adversaries, having named 11 new ones over the period, alongside more than 150 unattributed activity clusters.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Alessandro Mascellino
Alessandro Mascellino Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.