Cybersecurity

Microsoft: Attackers Are Gaining an Early Lead Over Defenders in Leveraging AI

In its 2026 Digital Defense Report, Microsoft warns that threat actors are currently benefiting from artificial intelligence faster than security teams, particularly in vulnerability discovery, malware development, and accelerating post-compromise activity. The company believes that the time needed to turn a discovered vulnerability into a weapon has fallen to less than 24 hours, although real-world campaigns still rely heavily on human direction.

2026-10-01
4 min read
14 views
certi.news Editorial Team
Microsoft: Attackers Are Gaining an Early Lead Over Defenders in Leveraging AI

Microsoft says that cyberattackers currently have an advantage over defenders in the race to leverage artificial intelligence, according to its 2026 Digital Defense Report. This advantage lies in reducing the time, expertise, and cost required to discover and exploit vulnerabilities, as well as in accelerating malware development and activities carried out after networks are breached.

The company acknowledges that artificial intelligence will provide security teams with similar benefits in the long term, but it believes that balance has not yet been achieved. According to its assessment, defenders need to move faster to close the gap because flaws are being discovered at a much faster rate than they are being fixed.

A Growing Gap Between Discovery and Remediation

Vulnerability research is the clearest area where this imbalance appears. While AI-powered tools can accelerate the discovery of flaws and the analysis of ways to exploit them, vulnerability remediation remains slower by nature, particularly in systems that lack robust unit and integration testing allowing software changes to be deployed quickly.

Microsoft warns that this could lead to a period lasting years during which the number of known, unpatched vulnerabilities increases. Well-organized and well-funded adversaries may also be able to stockpile large numbers of zero-day vulnerabilities discovered through these methods. The company adds that the average period between discovering a vulnerability in a real-world environment and turning it into an offensive tool has become far shorter than 24 hours, narrowing the correction window available to organizations.

From Malware Development to Lateral Movement

Offensive use is not limited to vulnerability discovery. Microsoft says that attacking groups use artificial intelligence to create customized malware and accelerate data and secret extraction, as well as lateral movement within networks—tasks that used to take days and may now be completed within minutes.

Automation also enables larger portions of the attack chain to be carried out with limited human intervention, giving less-experienced criminals capabilities previously associated with more sophisticated actors, including the customization of phishing and social-engineering messages. The company believes that advanced actors may shorten the attack chain from days to seconds, while these tools give less-sophisticated attackers a level of persistence previously limited to intelligence agencies.

Uses Attributed to Government Actors

Microsoft says that state-backed actors have already begun using artificial intelligence in real-world operations. Chinese state-linked actors have used AI tools to search for vulnerabilities and learn how to exploit them, while continuing to rely on phishing and remote-access trojans. The company also detected Russian actors using “vibe coding” and AI-generated tools to accelerate attacks.

According to the report, North Korean technical workers operating remotely use artificial intelligence to build fictional personas, conduct social engineering, and maintain access to organizations, while other actors use it to develop malware and manage attack infrastructure. Microsoft also points to the use of agent-based workflows and code generated by large language models to accelerate malware deployment.

What Has Not Changed Yet?

Despite this acceleration, Microsoft does not say that attacks have become fully autonomous. Most observed campaigns still rely on humans to select targets, make decisions, and handle the complex parts of the operation. This currently places artificial intelligence in the role of a tool for expanding and accelerating attackers’ capabilities, not a complete replacement for the human operator.

Editorial reading: The most important change is not the emergence of fully autonomous attacks, but the shrinking interval between discovering a weakness and exploiting it, along with the expansion of the range of actors capable of carrying out customized operations. This suggests that relying solely on slow, manual remediation will leave organizations with a narrower protection window. At the same time, the report remains an assessment issued by Microsoft, and the material presented does not provide independent measurements separating the extent of AI’s contribution to each campaign or proving that all the cited uses reached the same level of automation.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news