- Microsoft declared that threat actors are presently reaping AI advantages at a faster pace with regard to vulnerability finding and attack automation.
- According to the report from the corporation, weaponizing a vulnerability may happen in less than 24 hours after discovery.
- The company encourages defenders to use AI technologies together with better identity and exposure management, data protection, and mitigation.
Modern cyber-attacks are changing methods of operations by utilizing artificial intelligence. Microsoft says threat actors are currently using AI to speed up vulnerability discovery, malware development, and actions after gaining access.
The warning appears in Microsoft’s 2026 Digital Defense Report, released October 1. The report says attackers currently benefit from AI’s speed and scale, while defenders work to close the growing gap.
AI is Shortening the Time Between Discovery and Attack
Microsoft says AI is changing the pace of cybersecurity on both sides. However, the company sees attackers gaining some benefits sooner, especially when they search for software weaknesses.
According to the report, CVEs amounted to nearly 40,000 in the first six months of 2026. The rate of occurrences means that this year could deliver two times as many incidents as last year. AI can assist scientists in reviewing code and locating issues much faster.
The main problem here is the length of time between the detection and usage of a vulnerability for an attack. Microsoft says the median period has fallen well below 24 hours. Defenders often need much longer to fix serious weaknesses. Microsoft estimates that enterprise remediation for critical external vulnerabilities can take 30 to 60 days. That creates a large window for attackers to act before organizations complete their fixes.
Microsoft also points out that attackers can design databases of undiscovered vulnerabilities. Therefore, rich groups will wait with those vulnerabilities until they find their ideal victim. On the other hand, AI reduces the qualifications required for committing some crimes. This means criminals with little practice can use those technologies to perform crimes that took a lot more skills before.
Attackers are Using AI Across the Attack Chain
Vulnerability research represents only one part of the change. According to Microsoft, the threat actors are also using AI with different points of the attack chain such as reconnaissance, phishing, malware development, and other operations after their attacks. The AI tools can enable attackers to provide specific types of attack. Also, they can speed up processes like finding secrets, stealing data, and covering various systems.
The sources state that AI can cut down some aspects of an attack into seconds rather than days. This is why some advanced groups are now able to automate repetitive tasks. Also, less-tech criminals have all it takes to launch attacks that previously required more skills.
The report also highlights the growing use of AI by state-sponsored threat actors. Microsoft says Chinese groups have used AI to support vulnerability research and exploitation efforts.
The Russian state-affiliated actors are known to apply AI-generated tools and other so-called vibe-coding techniques. The North Korean operators have applied AI for persona creating and social engineering. The North Korean attacks were also noted to apply agentic structures and massive language model-generated codes. These approaches aid the attackers to operate fasters and reduce most manual tasks.
Despite the major role of AI, Microsoft still claims that modern cyberattacks are not totally automated. There are the roles of human operators, such as choosing targets, taking certain decisions plus overseeing some complex stages of their campaigns.
Defenders Face a Growing Remediation Gap
The speed difference creates a difficult problem for security teams. While AI helps defenders to identify vulnerabilities faster – it still takes input from live systems to seal the gaps.
Software teams require various tests, deliberations, and implementations before they can release security patches. These steps can take longer than the automated process of discovering the vulnerability. Consequently, Microsoft expects organizations to face a period with more known but unpatched vulnerabilities. Moreover, attackers can use that gap in the fixing period to target such systems before defenders complete their mitigation.
The company also says organizations need to move beyond traditional patch counts. Security teams should concentrate more on lessening their vulnerability, better detection, and reducing the time for serious risk mitigation. Due to this, Microsoft advises focusing more on identity protection, least privilege, software security, data security, and vulnerability management.
These efforts remain relevant even when attackers are using AI for their missions. Many attacks still begin with familiar weaknesses, including compromised accounts, user actions, exposed systems, and trusted services. Microsoft has also warned Windows users about a separate threat involving a false Defender antivirus alert designed to trick them into taking action.
The latest report from Microsoft says user execution accounted for 30% of observed initial access. Valid accounts accounted for another 20%. That means AI has not replaced older attack methods; it can just make those methods faster and easier to scale.
Microsoft Pushes for Faster AI-Assisted Defense
Microsoft believes that with the growing acceptance of AI systems in the industry, the power dynamics of the conflict between cyber-attackers and defenders should shift. The firm is already implementing AI tools in its own practices involving vulnerability detection, analysis and mitigation.
Earlier this year, in April, Microsoft informed the public that the cutting-edge models of AI were capable of locating loopholes, uniting minor bugs, and creating potentially working exploit codes. The company suggests that cyber-defenders would be able to exploit similar technology to detect and fix vulnerabilities faster than it is possible now.
The 2026 report of the company integrates this technological advance into the practice of cyber-defense. Thus, Microsoft wants organizations to combine threat intelligence with enterprise context and security signals. This move will aid them in determining which alerts are the most important for them. Also, this focus can help defenders to signal alerts before the exploitation is possible.
At the same time, Microsoft mentions that organizations should take care to protect AI systems as well. It noted an AI agent is capable of gaining access to identities, systems, data, applications, etc., via excessive permissions. The company therefore sees AI as both a growing attack tool and a defensive resource. The immediate challenge involves closing the speed gap while maintaining basic security controls.
Further, Microsoft says human oversight still plays a major role in real-world attacks. However, the increasing use of automation suggests that security teams may need to make decisions faster as AI capabilities continue to develop.
Share this article
About the Author
Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.
More from Farwa SajjadRelated Posts
Signal Expands Encrypted Backups and Private iPhone Transfers in Version 8.30
Signal version 8.30 adds on-device backups to iOS and Signal Desktop. The update separates media fil...
Hacker Claims 4.5 Million Records Linked to Italian Hotel Software Firm WuBook Leaked
An underground forum user says they leaked 4.5 million names and IDs tied to WuBook, an Italian hote...
Armenian Ryuk Ransomware Hacker Sentenced to 2 Years in US Prison
Armenian national Karen Vardanyan received 24 months in prison and three years of supervised release...
Leaked EU Draft Could Let AI Companies Use Personal Data Without Consent
A leaked EU document could let AI companies use personal data without your consent. The draft remove...
Dark Web Seller Claims Android 14–16 Zero-Day Exploit Chain is for Sale
A dark web operator, xynapse, offers an unconfirmed zero-day exploit chain for Android versions 14 t...
Ukrainian Ransomware Developer Sentenced to Nearly 13 Years in Switzerland
A court in Zurich handed a 52-year-old Ukrainian man a sentence of 12 years and nine months for his ...