Cloud · 53 days ago
Supply-chain compromise is no longer a one-off poison pill. The new break is that stolen developer credentials are being reused in later intrusions, so a package breach can keep feeding new attacks long after the original package is removed.
Wiz says H1 2026 saw significant incidents up 60% from H2 2025, with supply-chain attacks more than doubling to about 25% of its highlighted cases. It tracked activity across npm, PyPI, Composer, VSCode extensions, Jenkins plugins, and AUR, and says TeamPCP, North Korea-linked operations, and others used poisoned packages to harvest credentials that later showed up in other actors’ campaigns months later.
CrowdStrike and Cisco Talos add the acceleration layer: attackers are using AI to generate exploits, phishing, recon, and credential-harvesting workflows, and 88% of observed exploitation with public PoC code happened within 48 hours. That makes the same trust chain faster to abuse and harder to clean up once credentials have been exposed.
5 sources covering this story
Cloud Threat Highlights: H1 2026 | Wiz Blog
Cloud and AI threat activity tracked by Wiz Research and CIRT, January through June 2026
Suppliers, logins, and AI tools are all becoming attack paths - Help Net Security
AI, cloud attacks, software supply chains, and vishing dominate the latest cyber threat trends in CrowdStrike's new report.
Evidence points to cybercriminals stepping up their AI game
Reports from Cisco Talos and CrowdStrike provide real-world insights into how AI is evolving attackers’ tradecraft and becoming part of their day-to-day operations.
CrowdStrike: AI is now both the weapon and the target in cyberattacks
Meanwhile, attackers are using AI to weaponize vulnerabilities faster than companies can patch them.
CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
The CrowdStrike 2026 Threat Hunting Report shares observations and real-world case studies demonstrating an increase in attacks on trusted relationships and adversarial use of AI.
Part of the PlainSec briefing for 2026-08-07