CrowdStrike’s 2026 Global Threat Report reported that in 2025 adversaries took 29 minutes on average to move from initial access to lateral movement (“breakout”) inside victim environments, representing a 65% acceleration versus the prior year. The report also cited extreme cases, including a 27-second breakout and an instance where data exfiltration began within four minutes of initial compromise, underscoring that intrusion speed is increasingly central to attacker success and evasion.
The findings were attributed to a combination of credential misuse, increased attacker efficiency (including the use of AI-enabled tooling), and persistent defensive blind spots that reduce detection and response windows. DataBreaches.net amplified the same CrowdStrike metrics and pointed readers back to the Dark Reading coverage, reinforcing the operational implication for defenders: response processes and controls must assume materially shorter dwell times between initial compromise and impactful actions (lateral movement and exfiltration).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
CrowdStrike released its 2026 Global Threat Report, framing 2025 as the 'year of the evasive adversary' and emphasizing faster breakout times, identity abuse, AI-enabled operations, cloud targeting, and zero-day exploitation. Multiple outlets summarized the report's findings after publication.
During 2025 threat monitoring, CrowdStrike said attackers exploited CVE-2025-3248 in Langflow, including in ransomware-related activity. It also reported a spoofed Postmark MCP server published to npm to harvest sensitive data and malicious prompt injections observed at at least 90 organizations.
CrowdStrike reported that AI-enabled adversary activity rose 89% in 2025, while cloud-conscious intrusions increased 37% overall and 266% among state-nexus actors. The report also highlighted a 42% year-over-year increase in zero-day exploitation, especially against edge devices with limited visibility.
Across 2025 investigations, CrowdStrike reported that 82% of detections were malware-free and that valid-account abuse featured heavily in cloud incidents, including 35% of cloud-related cases. The findings described attackers using trusted identity flows, SSO, SaaS integrations, and cross-domain movement to evade detection.
In its analysis of 2025 threat activity, CrowdStrike found the average time from initial compromise to lateral movement fell to 29 minutes, a 65% year-over-year acceleration. The company also recorded a fastest observed breakout of 27 seconds and one case where data exfiltration began four minutes after initial access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechtarget.com
Open sourcecsoonline.com
Open sourcecardinalops.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.