Skip to content
Opens in a new window
Unpacking the CrowdStrike 2026 Threat Hunting Report with CrowdStrike’s Katie Blankenship
03 August 2026

Unpacking the CrowdStrike 2026 Threat Hunting Report with CrowdStrike’s Katie Blankenship

Adversary Universe Podcast

About

The CrowdStrike 2026 Threat Hunting Report is now live! The report sheds light on how our threat hunters and analysts hunt and defend against the world’s most sophisticated adversaries. It’s packed with stories from the front lines and trends that define the modern threat landscape.

Joining Adam to dig into its findings is Katie Blankenship, Sr. Manager of the Global Threat Analysis Cell for the CrowdStrike Counter Adversary Operations team. Katie, who leads the charge for our major intelligence reports, explains the herculean effort that goes into distilling a year’s worth of events into a single report. The CrowdStrike 2026 Threat Hunting Report is the product of seven trillion events analyzed, 14 million daily detection leads, and 36,000 annual customer alerts and notifications.

So what did they tell us? These are some key takeaways covered in this episode:

The window between vulnerability disclosure and exploitation is collapsing. From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public proof of concept (PoC) was conducted within 48 hours of the PoC’s release. China-nexus adversaries VAULT PANDA and GENESIS PANDA, both highly active in the last six months, are monitoring vulnerability disclosures so they can quickly weaponize them.

Adversaries are targeting the developer ecosystem. Software supply chain attacks aren’t new, but adversaries are seeing opportunities to exploit trust relationships in this pipeline. ALTERED SPIDER is one of them — this adversary compromised 300+ software dependencies in one day, harvested credentials, and pivoted into cloud environments.

Technology and finance are in the crosshairs. Technology was the most targeted sector for the ninth year running. DPRK-nexus adversary FAMOUS CHOLLIMA’s operations accounted for 55% of all state-sponsored intrusions targeting this sector. The financial services sector saw an 11% year-over-year increase in targeting, with FAMOUS CHOLLIMA driving activity there as well.

Tune in to hear Adam and Katie discuss the CrowdStrike 2026 Threat Hunting Report’s most interesting stories, stats, and adversaries in an episode that Adam calls “the podcast for those who didn’t want to read the 48-page report.”

Methodology & Source: All information provided is based on the CrowdStrike Counter Adversary Operations team’s proprietary threat intelligence gathered between July 1, 2025, and June 30, 2026. Stats may include data from the entire period surveyed or excerpts of data from specific date ranges within the period.