Here are the three findings I think IT leaders should actually act on after reading the CrowdStrike 2026 Threat Hunting Report.
I expected the usual from this year's report. Bigger numbers from state-funded hackers with everything up and to the right.
That's not what I am seeing.
Overall, intrusions grew about 4% this year, down from 27% last year. That sounds like good news, right?
It’s not. The security landscape is changing. The attackers' scope is changing.
Adversaries are not slowing down. They are running more precise attacks that follow a pattern. Almost every big finding describes an attacker walking through doors someone left open for them.
Three of those doors matter the most with none requiring buying another product.
Security Gap One: Code You Did Not Write
In the first half of 2026, malicious npm packages made up 87% of all malicious software activity. One malicious group compromised more than 300 software dependencies in a single day, using malware that publishes infected versions of other packages on its own.
This is scary knowing that today’s vibe coders aren’t vetting what they’re using.
Take a look at the incident at Trivy.
In March, attackers got into the Trivy’s GitHub Action repository and pushed malicious commits using the same version numbers teams were already pulling.
Every organization referencing those tags ran credential-stealing code inside their own pipeline. The code went looking for cloud access keys, Kubernetes tokens, SSH private keys, and container registry credentials.
What I’ve learned is to pin your GitHub Actions and dependencies to commit SHAs instead of version tags.
Do this: pin to SHAs to prevent supply chain attacks, and put phishing-resistant MFA on every package registry and repository account.
Security Gap Two: Someone Calling Your Staff Pretending To Be IT
This is the one I keep thinking about, because it is aimed at people like me.
Vishing intrusions doubled in the first half of 2026 compared to the second half of 2025. That came on top of a 134% jump the year before.
Their playbook is simple. Call the user on their personal phone, where you have no visibility and jurisdiction. Say you are from IT and there’s a small issue with their account. Walk them to a page that looks exactly like their normal sign-in, or just ask them to approve a push prompt.
In one case, once the attacker had the account, they were exporting files out of their organization in under five minutes.
The obvious risk is data loss. The one I think is worse is what this does to your relationship. This attack works by taking advantage of the trust between your people and whoever helps them with technology. When that gets compromised, staff get suspicious of IT.
Here is the part that should change how you think about security.
In most cases the attackers never touched a managed endpoint. They logged into a cloud identity and enrolled their own MFA device.
If your monitoring stops at the agent on the laptop, you are running blind.
What can caught one of these is an alert on a new MFA device enrollment. A behavior most organizations already have available but not enabled.
The strongest control here costs nothing.
Think about making this a rule: IT will never call an employee on their personal phone to set up SSO, passkeys, or MFA. If someone does, hang up and call a known number.
That part needs your executive support, not a new tool on the security budget.
Do this: turn on MFA enrollment alerting, and write the callback rule.
Security Gap Three: The AI Nobody Owns
This is the finding I do not think most IT leaders have thought of yet.
Attackers have pivoted their attacks from using AI as a tool to now becoming a target.
The report documents attackers stealing corporate access to large language models and reselling it. In one case an attacker pushed roughly 200,000 API requests in a two minute burst against a victim's account. The most common AI-related technique was running up a victim's AI bill.
Attackers have been caught delivering a malicious MCP server configuration that reads internal environment variables from its process and sends them to an external webhook.
From what I’m seeing and hearing, AI adoption happened as shadow IT. Someone in marketing has an API key for their CRM. A developer is running MCP servers pulled from a repo they found last month. A department bought an AI tool and connected it to internal file storage.
None of that is in a CMDB. Nobody scoped those credentials, because nobody knows they exist.
The real problem is ownership. AI governance needs to take place. Finance sees the bill but IT owns the risk to a purchase they didn't approve. The department that bought the tool owns neither.
This might not be a security gap in most organizations but it is a governance problem that becomes a security problem the first time a secret key leaks.
Do this: inventory first, controls second. List every AI API key, MCP configuration, and service account. Then enable spend anomaly alerts or spend maximums.
My Takeaway
Supply chain, IT impersonation, and AI sprawl look like three separate problems but they are the same problem.
In each case an organization delegated trust to something outside its direct control, which is an easy thing to do, and then never built governance around it.
You trusted a package maintainer. You trusted that a call claiming to be IT was IT. You trusted that whoever set up that AI integration scoped permissions correctly.
The question I would start asking:
What have we delegated trust to that we have never documented?
You do not answer that question with a product. You answer it with an inventory and a written policy or process.
The three things above cost almost nothing. None of them require calling a vendor or consultant.
The post Attackers Aren’t Breaking In appeared first on Packet6 | Enterprise Networking, Wi-Fi & Managed IT.
Packet6
Inc. Magazine
Van Clan
Ars Technica
The Right Scoop
Start at Home Decor
Bryson Real Estate Blog