2 OCT 2026 — For most of the history of hacking, the slow part of an attack was finding a flaw worth using. Microsoft's annual Digital Defense Report, published on 1 October, says AI is making that step quick and cheap, and that organisations cannot fix flaws as fast as they are now being found. The company expects the gap to last for years.
The report covers July 2025 to June 2026 and draws on what Microsoft's security and threat intelligence teams observed over that period.
Finding has outrun fixing
The report says new analysis tools have driven the number of known vulnerabilities up sharply, and that helps attackers as much as defenders. "Remediation is inherently much slower than discovery," it says, because many systems lack the testing needed to ship code changes quickly.
Microsoft describes the result as "a multi-year period where the number of known but unpatched vulnerabilities spikes." It adds that well-funded adversaries "may be able to stockpile large numbers of zero-day vulnerabilities" found this way.
Microsoft estimates that a record 72,000 vulnerabilities will be tracked as CVEs in 2026, and says the median time from a flaw being discovered in the wild to being turned into a working attack has fallen "well below 24 hours." Its own patching reflects the volume. We reported in September that Microsoft had already patched 2,760 flaws this year, more than double its previous annual record.
What attackers are using AI for
The report says adversaries now use AI to find vulnerabilities in source code, compiled software and AI serving systems, and to write custom malware. Once inside a network, AI shortens the work of stealing data, finding secrets and moving between machines from days to minutes, and in some cases it manages the whole attack chain.
None of these are new attack methods, Microsoft says. The problem for defenders is how much faster and larger attacks have become. It also identified Russian state actors using "vibe coding or AI-generated tooling", while concluding that for now AI improves their scale and speed rather than changing how they attack.
The first steps towards autonomous attacks
In laboratory evaluations, Microsoft says, Anthropic's Mythos and OpenAI's GPT-5.5 were the first models to show they could run a complex attack on their own. Both achieved full control of an emulated company network through a 32-step attack chain, though the test system had no defenders. Open-weight models, whose weights anyone can download, lag closed models at this by seven months, the report says.
Outside the lab, the report says early July 2026 saw the first documented automated ransomware extortion attack, an event the security firm Sysdig named JADEPUFFER. Microsoft says it has seen AI-run intrusions that share elements with that activity. Volumes remain low, and the way in has consistently been internet-facing services running software with known flaws.
Where Southeast Asia fits
The report does not break its AI findings down by country. In its section on where attacks land, it says Microsoft has seen "growing cybercriminal activity impacting Latin America, Africa, and Southeast Asia", regions where defences may be less mature while digital transformation is speeding up.
That gap matters most in those places. Organisations that patch slowly are the ones a fast exploit cycle punishes first.
What Microsoft expects next
The report expects software makers using AI to find and fix their own flaws to produce more secure code, after an initial wave of large patches. Even then, it says, attackers will keep turning new flaws into exploits within hours, so fast patching will remain necessary.
Microsoft also expects defenders to rely more on people working alongside AI systems and to give those systems more autonomy to act. Its accompanying blog post is notably milder than the report itself, describing AI as giving "defenders new ways to find and address weaknesses while giving cyberattackers new ways to look for them."
Disclosure: RECATOOLS is written with the assistance of Claude, made by Anthropic, whose Mythos model is one of the two the report names. Readers should weigh that interest.