Summary
- CrowdStrike says 88% of observed exploitation involving vulnerabilities with public proof-of-concept code occurred within 48 hours.
- Its telemetry also recorded a 171% increase in cloud-focused criminal activity and sharp growth in device-code phishing.
- The figures reflect CrowdStrike’s customer and threat-hunting visibility rather than a universal measurement of all attacks.
CrowdStrike says 88% of the exploitation it observed involving vulnerabilities with public proof-of-concept code occurred within 48 hours of release during the first half of 2026.
CrowdStrike said some state-linked activity moved faster, with two China-nexus groups launching deliberate attacks within 24 hours of disclosure of a critical web-application vulnerability.
The findings form part of CrowdStrike’s 2026 threat-hunting report and are based on the company’s proprietary telemetry and investigations. They describe activity visible across CrowdStrike’s customer base rather than providing a comprehensive measurement of every vulnerability or intrusion worldwide.
The figures are drawn from CrowdStrike’s own telemetry, but they describe an operational window narrow enough to challenge routine patch and change processes. Public exploit code can reduce the work required to reproduce a vulnerability, automate scanning, and identify exposed systems. Attackers can move from testing to mass targeting while some organisations are still identifying affected assets or waiting for a routine change window.
The report also identifies increased activity across cloud and identity environments. CrowdStrike recorded a 171% rise in what it calls cloud-conscious criminal activity, including credential theft, cryptomining, abuse of large-language-model services, and theft of digital financial assets.
Voice-phishing intrusions doubled during the same period, while monthly device-code phishing attempts increased fifteenfold. In one observed intrusion, attackers moved from account takeover to data theft in under five minutes after compromising a single sign-on-connected software service.
Those figures point to a risk model that is no longer centred on malware reaching a managed laptop. Attackers may enter through an internet-facing vulnerability, a cloud identity, a software dependency, a remote-access service, or a trusted authentication process, then move between those domains using legitimate tools and permissions.
The report says 87% of software-registry threats identified during the first half of the year involved malicious npm packages. It also describes one criminal group compromising more than 300 software dependencies in a day to collect credentials and gain access to cloud environments.
Software repositories and package ecosystems offer scale for the same reason that remote-management and identity platforms do: a single compromise can propagate through trusted operational relationships. The attacker does not need to target every downstream organisation directly if developers and automated build processes import the malicious component on its behalf.
The 48-hour exploitation figure also exposes the limits of patching metrics based only on eventual completion. An organisation may report strong monthly compliance while remaining exposed during the brief period when attackers are most active and the vulnerability has become easiest to reproduce.
Prioritisation therefore depends on more than severity scores. Internet exposure, available exploit code, observed activity, asset purpose, identity privileges, and the ability to detect compromise can change the order in which a vulnerability needs to be addressed.
There is a commercial context to the report. CrowdStrike sells products and services intended to detect the activity it describes, and its terminology reflects its own intelligence classifications. The statistics should be treated as vendor telemetry with substantial visibility, not as independent population-wide measurements.
Even with that qualification, the direction is consistent across the findings: public exploitation, cloud abuse, identity attacks, and software supply-chain compromises are moving at speeds that reduce the value of slow, domain-specific response processes.
Slow asset identification, fragmented identity and cloud monitoring, or lengthy change procedures can consume much of that window before remediation has begun.


