Microsoft says cyberattackers are gaining benefits from artificial intelligence faster than defenders, according to the company’s 2026 Digital Defense Report. The report says AI is speeding up vulnerability discovery, malware development and activity after attackers gain access to a system.
Microsoft says AI can lower the time, expertise and cost needed to find and exploit weaknesses. It also says the median time from discovery of a vulnerability in the wild to its weaponization has fallen well below 24 hours. Remediation often takes longer, the company says, because many systems lack robust testing and cannot deploy code changes quickly. Microsoft warns that known but unpatched vulnerabilities could rise for several years.
Attackers are also using AI to create customized malware and accelerate tasks such as data theft, finding secrets and moving through compromised networks. Microsoft says nation-state groups have used AI in real-world operations: some Chinese state-sponsored actors use it to research vulnerabilities, Russian actors have used “vibe coding” and AI-generated tools, and North Korean actors use it for persona development, social engineering, malware and attack infrastructure.
Microsoft says AI has not made cyberattacks fully autonomous. Most observed campaigns still rely on people to choose targets, make decisions and handle complex tasks, even as some systems demonstrate end-to-end autonomy in labs and early real-world cases.
Comments
0No comments yet. Be the first to comment.