---
title: "Evasive Adversary: CrowdStrike 2026 Global | Firevault"
url: https://fire-vault.com/news/evasive-adversary-crowdstrike-2026-global-threat-report
description: "The CrowdStrike 2026 Global Threat Report analysed trillions of security events across 281 tracked adversaries. Its findings, from 27-second breakout times to…"
lang: en-GB
---

Insight · 26 February 2026

# CrowdStrike 2026 Global Threat Report

The CrowdStrike 2026 Global Threat Report analysed trillions of security events across 281 tracked adversaries. Its findings, from 27-second breakout times to 82% malware-free intrusions, confirm that the most critical data must be stored beyond the reach of any network.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

9 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fevasive-adversary-crowdstrike-2026-global-threat-report
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fevasive-adversary-crowdstrike-2026-global-threat-report&text=CrowdStrike%202026%20Global%20Threat%20Report%0A%0AThe%20CrowdStrike%202026%20Global%20Threat%20Report%20analysed%20trillions%20of%20security%20events%20across%20281%20tracked%20adversaries.%20Its%20findings%2C%20from%2027-second%20breakout%20times%20to%2082%25%20malware-free%20intrusions%2C%20confirm%20that%20the%20most%20critical%20data%20must%20be%20stored%20beyond%20the%20reach%20of%20any%20network.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fevasive-adversary-crowdstrike-2026-global-threat-report

Image: Dark data centre corridor with deep navy lighting and magenta accents on server racks (https://fire-vault.com/images/news/crowdstrike-2026-threat-report.jpg)

Dark data centre corridor with deep navy lighting and magenta accents on server racks

Why it matters

## What this means for organisations holding critical data

## What This Report Covers

The CrowdStrike 2026 Global Threat Report is one of the most comprehensive annual assessments of the cyber threat landscape, drawing on trillions of telemetry events across endpoints, cloud workloads, identities, and networks. In 2025, CrowdStrike named 24 new adversaries, bringing the total tracked to 281.

This insight piece distils nine key findings from the report and examines what each means for organisations seeking to protect their most critical and sensitive data.

## 1. 82% of Detections Were Malware-Free

In 2025, 82% of all CrowdStrike detections were malware-free, up from just 51% in 2020. Adversaries are no longer relying on traditional malware. They operate through valid credentials, trusted identity flows, approved SaaS integrations, and inherited software supply chains.

This means conventional signature-based defences are detecting fewer than one in five intrusions. Adversaries blend into normal activity, moving through authorised pathways and trusted systems.

> **Firevault view:** When 82% of intrusions leave no malware signature, the question is not whether your detection tools will catch the threat, but what happens to your data when they do not. Data stored in a Firevault offline secure storage (https://fire-vault.com/products/firevault-oss) environment cannot be reached through any network pathway, regardless of how an adversary gained access to your digital estate.

### Malware-Free Detections (2020 to 2025)

Source: CrowdStrike 2026 Global Threat Report

## 2. 29-Minute Average Breakout Time, Fastest in 27 Seconds

The average eCrime breakout time fell to 29 minutes in 2025, a 65% increase in speed from the prior year. The fastest observed breakout took just 27 seconds. In one documented intrusion by CHATTY SPIDER, data exfiltration began within four minutes of initial access.

This compression of the attack timeline means that traditional incident response processes, which typically operate on timescales of hours or days, are fundamentally mismatched against the speed of modern adversaries.

> **Firevault view:** When the fastest adversaries are exfiltrating data in under 30 seconds, response speed alone is no longer a viable strategy. The only reliable protection is ensuring that the data they are seeking is not accessible from any connected system. Firevault's Layer 1 physical air gap (https://fire-vault.com/products/firevault-oss) removes the most critical data from the attack surface entirely.

### Average eCrime Breakout Time (Minutes)

Source: CrowdStrike 2026 Global Threat Report. Fastest observed breakout in 2025: 27 seconds.

## 3. 89% Increase in AI-Enabled Adversary Attacks

CrowdStrike observed an 89% year-over-year increase in attacks by AI-enabled adversaries. AI is being used to generate convincing phishing campaigns, create fake personas for social engineering, develop and obfuscate malware, translate lures into multiple languages, and even generate scripts for post-exploitation activities.

FAMOUS CHOLLIMA incorporated ChatGPT, Gemini, GitHub Copilot, and other AI tools into fraudulent employment operations. PUNK SPIDER used Gemini and DeepSeek to generate credential-dumping scripts. Two ransomware variants, FunkLocker and RALord, share encryption flaws specific to templates generated by the unrestricted AI model WormGPT.

> **Firevault view:** AI has lowered the barrier to entry for sophisticated attacks. Adversaries who previously lacked the technical expertise to develop custom tooling can now generate production-grade attack scripts in seconds. This democratisation of offensive capability means that every organisation, regardless of size or sector, faces threats that were previously reserved for nation-state targets. Offline secure storage (https://fire-vault.com/products/firevault-oss) provides a control that remains effective regardless of how the attack was generated.

### Top Industries Targeted by Interactive Intrusions (2025)

## 4. Supply Chain Attacks as Defining Tactic

In February 2025, PRESSURE CHOLLIMA executed the largest single financial theft ever reported, stealing $1.46 billion in cryptocurrency through trojanized software delivered via a supply chain compromise. This was not an isolated incident. Throughout 2025, adversaries systematically compromised upstream providers, development ecosystems, and public code repositories to gain broad access across downstream organisations.

In November 2025, threat actors compromised 690 npm packages to distribute the self-propagating information stealer ShaiHulud. In another attack, malicious Nx build packages were designed to use victims' own local AI CLI tools (Claude, Gemini) to generate commands that would steal authentication materials.

> **Firevault view:** Supply chain compromise is uniquely dangerous because it exploits the very trust relationships organisations rely upon. When adversaries can weaponise your own development tools and trusted software updates, every connected system becomes a potential entry point. Data that is physically separated from the network (https://fire-vault.com/our-difference/technology) cannot be reached through any compromised supply chain pathway.

## 5. 37% Rise in Cloud-Conscious Intrusions

Cloud-conscious intrusions rose 37% year-over-year in 2025. The increase among state-nexus threat actors was 266%. Valid account abuse accounted for 35% of all cloud incidents, reinforcing that identity has become central to intrusion.

Both eCrime and targeted intrusion adversaries evolved their cloud-targeting techniques, successfully subverting the implicit trust users place in cloud entities and technologies to achieve persistence, lateral movement, and data exfiltration.

> **Firevault view:** The 266% increase in state-nexus cloud attacks signals a structural shift in how nation-state adversaries operate. Cloud environments are now primary targets, not secondary ones. For organisations storing sensitive or regulated data in cloud environments, the question is not whether these environments will be targeted, but when. Firevault provides a Layer 1 physical air gap (https://fire-vault.com/products/firevault-oss) that ensures the most critical data remains beyond the reach of any cloud-based attack.

### Year-over-Year Increase in Key Threat Vectors (2025)

## 6. China-Nexus Activity Increased 38%

China-nexus adversaries increased their activity by 38% across all sectors. Attacks targeting logistics increased by 85%, telecommunications by 30%, and financial services by 20%. These adversaries systematically exploited vulnerabilities in VPN appliances, firewalls, gateways, and other internet-facing systems to establish long-term access for intelligence collection.

In 67% of the vulnerabilities China-nexus adversaries exploited, the flaw provided immediate system access. Newly disclosed vulnerabilities were weaponised within days of their public release. In one long-running intrusion, an adversary maintained persistent access for 22 months.

> **Firevault view:** The 22-month persistent access finding is particularly concerning for UK organisations in telecommunications, financial services, and logistics. These are precisely the sectors covered by NIS2 (https://www.gov.uk/government/publications/proposal-for-legislation-to-improve-cyber-resilience-of-uk-critical-infrastructure) and sector-specific regulatory requirements. When adversaries can maintain undetected access for nearly two years, the only reliable safeguard for the most sensitive data is to ensure it was never accessible from the compromised network in the first place.

## 7. 42% Increase in Zero-Day Exploitation

CrowdStrike observed a 42% year-over-year increase in the number of zero-day vulnerabilities exploited prior to public disclosure. Of those exploited vulnerabilities, 40% targeted internet-facing edge devices, including VPN servers, mail servers, firewalls, and routers.

China-nexus adversaries demonstrated the ability to weaponise newly disclosed vulnerabilities within two to six days of public release. GRACEFUL SPIDER, an eCrime adversary, has repeatedly exploited zero-day vulnerabilities targeting internet-exposed enterprise web applications since 2020.

> **Firevault view:** Zero-day exploitation is, by definition, an attack that cannot be patched against in advance. When 40% of zero-days target edge devices that frequently lack endpoint detection coverage, even well-resourced security teams face an unavoidable gap. Offline secure storage (https://fire-vault.com/products/firevault-oss) closes this gap for the most critical data by removing it from any network-accessible infrastructure.

### Interactive Intrusions by Region (2025)

- North America
- East Asia
- South Asia
- South America
- Oceania
- Europe
- Other

## 8. Cross-Domain Evasion Redefines the Threat

The report identifies cross-domain evasion as the defining characteristic of 2025 intrusions. Adversaries exploit visibility gaps created by fragmented security controls across identity, SaaS, cloud, and unmanaged devices, chaining together access paths to stay off well-protected endpoints.

SCATTERED SPIDER and BLOCKADE SPIDER exemplified this approach, rapidly moving laterally across traditional servers, hypervisors, cloud environments, unmanaged hosts, and SaaS applications. In one incident, BLOCKADE SPIDER used a compromised SSO account belonging to an information security employee to access the organisation's own EDR user interface and modify detection rules.

> **Firevault view:** When adversaries can modify your own security tooling from within your environment, the entire software-based security model has a structural limitation. Every tool in the chain becomes a potential target. The Firevault architecture (https://fire-vault.com/our-difference/technology) operates on a fundamentally different principle: the most critical data is stored in a physically separated environment that cannot be reached, modified, or compromised through any digital pathway.

## 9. Ransomware Remains the Primary eCrime Threat

Despite improved detection capabilities and law enforcement disruptions, ransomware remained 2025's primary eCrime threat. The ecosystem proved remarkably resilient. Fake CAPTCHA campaigns surged by 563%, and spam email volume rose by 141% year-over-year.

PUNK SPIDER, the most active ransomware adversary in 2025, conducted 198 intrusions, a 134% increase year-over-year. This adversary increasingly used remote encryption via SMB shares, encrypting data without ever executing ransomware on managed hosts.

> **Firevault view:** Remote encryption via SMB shares is a technique specifically designed to bypass endpoint detection. When ransomware no longer needs to execute on your monitored systems, the entire detection model shifts. For organisations holding data subject to regulatory obligations or business-critical operations, a physical air-gapped copy (https://fire-vault.com/products/firevault-oss) stored in a Firevault Bunker (https://fire-vault.com/products/firevault-bunkers) provides the ultimate recovery assurance, ensuring that even a successful ransomware attack (https://fire-vault.com/threats/ransomware) cannot reach the backup of last resort.

## What This Means for UK Enterprises

The CrowdStrike 2026 Global Threat Report confirms a fundamental truth about the current threat landscape: the adversaries are operating inside your trusted systems, using your own tools, and moving faster than your response capabilities allow.

Software-based security remains essential. Detection, identity management, cloud security, and endpoint protection are all necessary layers. But the report makes clear that these layers are insufficient on their own when 82% of intrusions leave no malware signature and the fastest adversaries break out in 27 seconds.

The most secure data is the data that cannot be reached.

Firevault exists to provide that final layer of protection: a Layer 1 physical air gap (https://fire-vault.com/products/firevault-oss) that stores the most critical data in a physically separated, offline environment. No network connection. No digital pathway. No possibility of remote compromise.

For organisations subject to NIS2 (https://www.gov.uk/government/publications/proposal-for-legislation-to-improve-cyber-resilience-of-uk-critical-infrastructure), FCA (https://www.fca.org.uk/firms/operational-resilience), SRA (https://www.sra.org.uk/solicitors/guidance/cybersecurity/), or DORA (https://www.digital-operational-resilience-act.com/) requirements, offline secure storage (https://fire-vault.com/offline-secure-storage) is not a luxury. It is a compliance necessity.

Explore how Firevault protects your most critical data →: https://fire-vault.com/products/firevault-oss

**How Firevault helps**

- **Offline Secure Storage (https://fire-vault.com/offline-secure-storage)** keeps gold-copy data physically disconnected from the network, so a ransomware or exfiltration event cannot reach it.
- **Control (https://fire-vault.com/control)** gives boards and operators a single view of what is online, what is isolated, and what is recoverable across the estate.
- **Firebreak (https://fire-vault.com/firebreak)** delivers hardware-enforced disconnection at Layer 1, so exposed credentials or compromised network paths cannot become a route into the vault.

_Talk to Firevault about Disconnect to Protect® (https://fire-vault.com/about) for your organisation._

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## Access decided by you, not assumed by the network

Control by Firevault removes standing pathways and replaces them with connection windows you approve, so stolen credentials and compromised suppliers have nothing standing to abuse.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**No standing access**Paths exist only when you open them

**Verification**Identity confirmed before any connection is made

**Containment**A compromised account cannot reach what is disconnected

**Control**Every window and closure is under your command

Related Reading

## You may also find these useful

Insight

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. New research shows no hacking was required: server-side marketing API keys sat in the public JavaScript of all three airport websites, unrotated, for more than four years.

27 Aug 2026 8 min
https://fire-vault.com/news/manchester-airports-group-data-breach-87-million-customers-2026

Insight

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min
https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026

Insight

### Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

26 Aug 2026 3 min
https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026

Insight

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min
https://fire-vault.com/news/iran-linked-hackers-uk-power-plant-shutdown-2026

Insight

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min
https://fire-vault.com/news/gta-6-leaks-rockstar-development-footage-2026

Insight

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min
https://fire-vault.com/news/nine-pbs-archives-cloud-vendor-shutdown-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/evasive-adversary-crowdstrike-2026-global-threat-report#webpage",
    "url": "https://fire-vault.com/news/evasive-adversary-crowdstrike-2026-global-threat-report",
    "name": "Evasive Adversary: CrowdStrike 2026 Global",
    "description": "The CrowdStrike 2026 Global Threat Report analysed trillions of security events across 281 tracked adversaries. Its findings, from 27-second breakout times to…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/news/crowdstrike-2026-threat-report.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/evasive-adversary-crowdstrike-2026-global-threat-report#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/evasive-adversary-crowdstrike-2026-global-threat-report#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "CrowdStrike 2026 Global Threat Report",
        "item": "https://fire-vault.com/news/evasive-adversary-crowdstrike-2026-global-threat-report"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "CrowdStrike 2026 Global Threat Report",
    "description": "The CrowdStrike 2026 Global Threat Report analysed trillions of security events across 281 tracked adversaries. Its findings, from 27-second breakout times to 82% malware-free intrusions, confirm that the most critical data must be stored beyond the reach of any network.",
    "url": "https://fire-vault.com/news/evasive-adversary-crowdstrike-2026-global-threat-report",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/news/crowdstrike-2026-threat-report.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/news/crowdstrike-2026-threat-report.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/news/crowdstrike-2026-threat-report.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/images/news/crowdstrike-2026-threat-report.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-02-26T05:26:13.179886+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/evasive-adversary-crowdstrike-2026-global-threat-report"
    },
    "inLanguage": "en-GB",
    "articleSection": "Insight",
    "wordCount": 1655,
    "keywords": "CrowdStrike, Insight, data breach, cyber security, offline secure storage, data protection, physical air gap, CrowdStrike 2026 Global Threat Report, evasive adversary, malware-free intrusion, breakout time 27 seconds, AI-enabled cyber attack, supply chain compromise, cloud-conscious intrusion, China-nexus threat actor, zero-day exploitation, cross-domain evasion, ransomware resilience, NIS2 compliance",
    "articleBody": "## What This Report Covers The CrowdStrike 2026 Global Threat Report is one of the most comprehensive annual assessments of the cyber threat landscape, drawing on trillions of telemetry events across endpoints, cloud workloads, identities, and networks. In 2025, CrowdStrike named 24 new adversaries, bringing the total tracked to 281. This insight piece distils nine key findings from the report and",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  }
]
```