[UPDATE] CrowdStrike threat report finds AI embedded across adversary operations, 131 poisoned AI packages
CrowdStrike's 2026 Threat Hunting Report, published 3 August, reports China-nexus actors exploiting critical vulnerabilities within 24 hours of public proof-of-concept release and DPRK-nexus actors poisoning 131 trusted AI framework packages. It is vendor-published primary research, so read it as an interested party's measurement rather than a neutral one, but the direction is consistent with the Hugging Face incident. Fal.Con 2026 also sold out at a record pace on the same date, a demand read that does not depend on price action.