Artificial intelligence is not just helping defenders. Microsoft’s 2026 Digital Defense Report, covering July 2025 through June 2026, argues attackers are cashing in first.
The headline number is stark. A fresh vulnerability rarely stays quiet for long, and Microsoft puts the median gap between discovery in the wild and a working exploit at under 24 hours. Its analysts expect the tally of tracked CVEs for 2026 to set a record near 72,000, while remediation trails discovery, leaving a multi-year pile of known, unpatched flaws that well-funded actors can mine.
Break-ins look different too. Flaws in public-facing applications now account for 24 percent of cases, up from 15 percent. Phishing, meanwhile, was behind close to a quarter of the incidents, a share that roughly tripled over the previous twelve months. And when a breach began with a valid login, 52.2 percent of the time the intruders went on to gather more credentials.
State crews are folding AI into their work. Chinese actors use it to hunt vulnerabilities, North Koreans to build personas and malware, Russians to scale tooling.
The report flags malware with a model built in, including the s1ngularity attack that rode trojanized npm packages and leaked roughly 2,000 secrets from 225 victims, and PromptLock, an experimental encryptor fed by an open-weights model. It also notes the first documented automated extortion attack, dubbed JADEPUFFER, and warns that self-spreading AI worms are now feasible.
