
Microsoft says attackers are getting the benefit of AI first. The ways in are still the old ones.
Microsoft's 2026 Digital Defense Report says a vulnerability can be weaponised in well under a day and that phishing is behind almost a quarter of intrusions. Its own advice for defenders is mostly about identity and access, not AI.
Microsoft published its 2026 Digital Defense Report on 1 October. It covers threat activity observed between July 2025 and June 2026, and its central message, as BleepingComputer reported it, is that attackers are currently benefiting from AI faster than defenders. Microsoft's own wording is that "in the near term we are in a period where attackers are reaching to advantages first, and defenders will need to move sharply in order to close the gap".
Faster at both ends
Microsoft says the time between a vulnerability being discovered in the wild and being actively weaponised can be well below 24 hours, and it projects a record 72,000 publicly disclosed vulnerabilities in 2026. BleepingComputer quotes the report warning that "remediation is inherently much slower than discovery", and that the world is likely to see a multi-year period in which the number of known but unpatched vulnerabilities spikes. Once attackers are inside, Infosecurity Magazine reports, Microsoft says AI has shortened data theft, credential discovery and movement across a network from days to minutes.
How they get in
Phishing accounted for 23 per cent of observed intrusions in 2026, up from 7 per cent in 2025, Microsoft says. Infosecurity Magazine reports that exploitation of public-facing applications, meaning systems reachable from the internet, rose from 15 per cent of incidents to 24 per cent, which it notes is likely linked to attackers using AI to find vulnerabilities. Microsoft also found that 52.2 per cent of intrusions involving valid accounts led to further credential theft, and that dwell time, the period between an attacker getting in and being found, increased this year across multiple sectors. Government was the most targeted sector, at 27 per cent of observed activity.
Not fully automated yet
Microsoft is careful not to overstate it. BleepingComputer reports the company saying that "most observed campaigns still retain human direction", with people still choosing targets and handling the complex parts of an attack. Infosecurity Magazine reports that the report's recommendations for organisations centre on identity: phishing-resistant multi-factor authentication, tiered administration and strong control of privileged access. In Microsoft's words: "Most of what we exploit there has nothing to do with AI. The core failure is the one red teams have exploited for years: too much standing access, too loosely enforced."
What this means for your business
Faster attacks make the old basics more urgent, not less. Three things to check. First, anything of yours that faces the internet, such as a firewall, VPN, remote access gateway or email security appliance, needs patching in days, not at the next convenient weekend, and someone needs to be watching for the warnings. Second, phishing now accounts for almost a quarter of intrusions on Microsoft's figures, so MFA should be on every account, and the phishing-resistant kind where you can. Third, take admin rights away from everyday accounts, including your own; Microsoft's point about standing access applies to a ten person office as much as a large one. If you want help working through that list in Exeter or the wider South West, talk to us.
Sources
#WEARECOBALT
Ready when you are.
Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.