Webinar Description
Key Takeaways
- Virtual threat briefing examining how adversaries exploit trust relationships across digital infrastructure
- Covers emerging attack vectors targeting AI systems, cloud environments and developer workflows
- Designed for SOC analysts, threat hunters, CISOs and incident response professionals
- Addresses rapid vulnerability exploitation and identity-based compromise techniques
- Presents frontline intelligence from CrowdStrike’s OverWatch threat hunting team
Introduction
The CrowdStrike 2026 Threat Hunting Report briefing, titled “Weaponized Trust: Inside the CrowdStrike 2026 Threat Hunting Report,” is a virtual event presenting findings from the company’s OverWatch threat hunting team. The briefing targets cybersecurity professionals responsible for defending enterprise environments against sophisticated adversaries. At its core, the event examines a fundamental shift in attacker methodology: the systematic exploitation of trust relationships that organisations depend upon for daily operations.
This focus on weaponised trust reflects a broader industry concern. As enterprises increasingly rely on interconnected cloud services, third-party integrations and automated development pipelines, the attack surface has expanded beyond traditional network perimeters. Adversaries have adapted accordingly, targeting the implicit trust between systems, identities and workflows rather than attempting to breach hardened defences directly.
About This Event
The virtual briefing delivers intelligence gathered from CrowdStrike’s frontline threat hunting operations. The OverWatch team, which conducts continuous monitoring and proactive threat hunting across customer environments, provides the primary source material for the report’s findings. Senior leaders in threat intelligence and field chief technology officers present the analysis, offering perspective on both the technical details and strategic implications of observed adversary behaviour.
The format emphasises actionable intelligence over theoretical discussion, aiming to provide security teams with specific indicators and patterns they can apply to their own detection and response programmes.
Emerging Attack Vectors Against AI and Cloud Infrastructure
A significant portion of the briefing addresses threats targeting AI infrastructure, including techniques such as cost harvesting and LLMJacking. These attack patterns exploit the computational resources and API access associated with large language model deployments. As organisations integrate AI capabilities into their operations, adversaries have identified opportunities to hijack these resources for their own purposes, whether for financial gain through unauthorised compute usage or for leveraging AI capabilities in subsequent attacks.
Cloud environments face parallel challenges. The briefing examines how attackers abuse trusted cloud access to steal secrets, hijack compute resources and create financial impact through resource consumption. These techniques often bypass traditional security controls because they operate within the boundaries of legitimate access, making behavioural detection and anomaly identification essential countermeasures.
Developer Workflow Compromise and Rapid Vulnerability Exploitation
The report highlights the compromise of developer workflows as a particularly concerning trend. By targeting development environments and continuous integration pipelines, adversaries can achieve downstream impact that extends far beyond the initial point of compromise. This supply chain approach allows attackers to inject malicious code or gain persistent access through trusted software delivery mechanisms.
Equally pressing is the accelerating timeline between vulnerability disclosure and active exploitation. Security teams face shrinking windows to assess, prioritise and remediate newly disclosed vulnerabilities before adversaries weaponise them. The briefing addresses this operational challenge, examining how threat actors have compressed the exploitation cycle and what defensive strategies can help organisations respond effectively.
Identity Compromise and Data Theft
Phishing and identity compromise remain foundational elements of many attack chains. The briefing explores how adversaries leverage compromised credentials to move laterally within environments, escalate privileges and ultimately exfiltrate sensitive data. In trust-based attacks, valid credentials provide attackers with the appearance of legitimacy, complicating detection efforts that rely on distinguishing malicious activity from normal user behaviour.
Who Should Attend
The briefing is designed for security professionals with operational responsibility for threat detection and response. Security Operations Centre analysts and dedicated threat hunters will find direct applicability in the tactical intelligence presented. CISOs and security executives can use the strategic insights to inform risk assessments and resource allocation decisions. Incident response teams and security architects in high-risk sectors such as finance, healthcare, government and technology will benefit from understanding the specific techniques adversaries employ against organisations in their industries.
Conclusion
As adversaries increasingly target the trust relationships that underpin modern enterprise infrastructure, security teams require current intelligence on evolving tactics and techniques. This briefing offers an opportunity to learn from frontline observations and apply those insights to strengthen defensive postures against sophisticated, trust-exploiting threats.

