CrowdStrike research says cloud crime surges via trusted accounts
CrowdStrike threat-hunting research says attackers increasingly enter via trusted cloud identities, tokens, applications, software dependencies and legitimate authentication, rather than only perimeter breaches. AI is used as both tool and target, including credential theft and cost-harvesting that drives higher AI-service spend. After React2Shell, CrowdStrike issued 800 leads across 80 victims; ALTERED SPIDER modified 300 dependencies and North Korea-linked STARDUST CHOLLIMA injected malicious code into at least 131 Mastra packages.