Microsoft: Flaws Weaponized in Under a Day

Microsoft this week published its 2026 Digital Defense Report, covering July 2025 through June 2026. Its headline conclusion: in this early phase of AI-driven cyber conflict, attackers are the ones cashing in first.

The starkest figure is the timing gap. The report says the median time from a vulnerability being discovered in the wild to being weaponized has fallen to "well under 24 hours," while enterprises typically take 30 to 60 days to patch a critical flaw exposed to the internet. Microsoft notes that AI can't skip the full unit and integration testing production systems require before a code change ships.

What Attackers Are Doing With AI

The report breaks AI's role in the attack chain down in detail: finding vulnerabilities, writing custom malware, and — after a breach — exfiltrating data, hunting for credentials, and moving laterally. Steps that used to take days can now be compressed into minutes.

Nation-state actors are already putting AI to work. By Microsoft's accounting, China-linked groups use it mainly to search for vulnerabilities and exploitation methods; Russia-linked groups use AI to generate tool code; North Korea-linked groups apply it to fake identities, social engineering, malware authoring, and supply-chain attacks; and Iran-linked groups continue to adopt it.

Entry points are shifting too. Phishing email's share of initial intrusions rose from 7% the previous year to 23%, while exploitation of internet-facing application vulnerabilities climbed from 15% to 24%. CVE counts are climbing as well: nearly 40,000 were published in the first half of 2026, and Microsoft expects roughly 72,000 for the full year — reportedly about double the 2025 total.

Fully Autonomous Attacks Already Exist

The report cites two kinds of cases. One is from a controlled environment: Anthropic's Mythos Preview and OpenAI's GPT-5.5 each carried out 32 consecutive attack steps in a simulated corporate network and took over the entire domain without human direction. The other is from the real world: JADEPUFFER, which security firm Sysdig documented this past July, is considered the first well-documented case of fully autonomous ransomware, with an AI-orchestrated system picking its own targets, issuing ransom notes, and managing the entire extortion process on its own. Microsoft says it has since observed a small number of intrusions with similar characteristics.

The report also notes that open-weight models lag roughly seven months behind closed models in attack-orchestration capability.

Still, Microsoft stops short of overselling the trend. It writes that in most of the campaigns it observes, target selection, decision-making, and execution of the most complex intrusions remain human-driven:

"Target selection, operational decision-making, and execution of the most complex intrusions remain manually driven in the majority of campaigns we observe."

A Parallel Verdict From UK Financial Regulators

Around the same time, the UK's Financial Conduct Authority (FCA) published a review of financial institutions' use of frontier AI models, reaching a similar conclusion: cyber-capable frontier models are finding vulnerabilities faster than remediation teams can process them, turning patching into the bottleneck and challenging traditional vulnerability-prioritization methods.

One is among the world's largest software makers, the other a financial regulator — different data sources pointing at the same gap: discovery has gotten faster, remediation hasn't. Microsoft's recommendations center on identity and access: the report says 78% of attacks on critical infrastructure rely on abusing cloud identities, so it lists phishing-resistant multi-factor authentication and passkeys as baseline requirements, and recommends managing AI agent permissions the same way human account credentials are managed.

What the report doesn't offer is how short the patching cycle can realistically get. The 30-to-60-day range comes from enterprise practice; AI is speeding up how fast patches get written, but Microsoft offers no forecast on whether testing and deployment pipelines can keep pace.

Sources: Microsoft 2026 Digital Defense Report, Help Net Security, CocoLoop, BleepingComputer, Tech Times; UK FCA frontier AI review summary. All figures follow Microsoft's reporting period.