THREAT actors linked to China, specifically groups Vault Panda and Genesis Panda, have demonstrated the ability to exploit critical vulnerabilities within 24 hours of their public disclosure, as reported by CrowdStrike. The recent acquisition of the React2Shell exploit allowed these groups to target web applications effectively.
CrowdStrike noted a broader trend where 88% of publicly disclosed vulnerabilities were exploited within 48 hours during the first half of 2026, indicating an increasing pace of cyber-attacks. Additionally, identity-based attacks are rising due to AI usage, with techniques such as LLMJacking and vishing becoming prevalent. The report emphasizes the challenges posed to cybersecurity, highlighting the impact of AI in accelerating the timeline of vulnerability exploitation.