Microsoft's 2026 Digital Defense Report, published this week with observations spanning July 2025 to June 2026, delivers an unusually blunt verdict on the AI security race: right now, attackers are getting more out of AI than defenders are. "While the equilibrium between attackers and defenders will likely ultimately be re-established, in the near term we are in a period where attackers are reaching to advantages first, and defenders will need to move sharply in order to close the gap," the report states.
The sharpest warning concerns vulnerability research. AI-assisted discovery is outpacing defenders' ability to remediate, and because many systems lack the unit and integration testing needed to ship code changes rapidly, Microsoft expects a multi-year period in which the number of known but unpatched vulnerabilities spikes. Well-prepared and well-funded adversaries, it adds, may be able to stockpile large numbers of zero-days found through such means. The median time between a vulnerability being discovered in the wild and weaponized has fallen "well below 24 hours," and the number of publicly disclosed CVEs is projected to reach a record 72,000 in 2026.
The compression extends across the attack chain. Microsoft says AI now lets sophisticated actors customize attacks at unprecedented speed and scale, reducing attack chains that once took days to minutes or even seconds, and accelerating post-compromise work such as data exfiltration, secret discovery and lateral movement. For less-skilled criminals, AI makes accessible the kind of persistent, tailored operations that were previously the domain of intelligence agencies - including social engineering for phishing and fraud.
The report documents state-sponsored groups already using AI in live operations, as Microsoft describes them: some Chinese state-sponsored actors use AI tools to search for vulnerabilities and learn how to exploit them while still relying on phishing and remote access trojans; Russian actors have been observed using "vibe coding" and AI-generated tooling to speed up attacks; and North Korean operations use AI for persona development, social engineering and LLM-generated malware, including fake IT-worker schemes built on deepfake personas. Microsoft is careful to note the limit: most observed campaigns still retain human direction, even as frontier systems demonstrate end-to-end autonomy in labs and early real-world cases.
On the defender's side, the picture is of a threat landscape getting harder to read. Government agencies and services were the most-impacted sector, accounting for 27% of observed activity, up from 17% a year earlier. Phishing accounted for 23% of observed intrusions, up from 7%, as attackers increasingly enter through techniques that mimic legitimate behavior. Dwell time - the gap between an attacker gaining access and defenders stopping them - increased across multiple sectors, and 52.2% of intrusions involving valid accounts resulted in additional credential theft.
Microsoft's prescription is less about new products than institutional speed: secure-by-design practices, stronger supply chain protections, bidirectional threat-intelligence sharing between the private and public sectors, and treating AI security as a resilience problem spanning models, infrastructure, data and suppliers rather than a narrow technical checklist.
The usual caveat applies: Microsoft sells security software, and an annual threat report is also a marketing document. But the specific numbers - sub-24-hour weaponization, 72,000 CVEs, a widening patch gap - are consistent with what vulnerability databases and security firms have been reporting all year. The uncomfortable conclusion stands regardless of who publishes it: discovery got fast before remediation did, and the imbalance will define the next few years of security operations.
Comments (0)
Log in to join the discussion
Log InNo comments yet