Microsoft: Attackers lead defenders in early AI race

Microsoft: Attackers lead defenders in early AI race

Microsoft says cyberattackers are currently getting more out of artificial intelligence than the people defending against them. According to the company, AI helps threat actors find vulnerabilities faster, build malware more quickly and move through compromised networks at a pace security teams struggle to match.

The findings come from Microsoft's 2026 Digital Defense Report, the company's yearly overview of the threat landscape. This year's edition focuses on how AI is reshaping both attack and defense.

Microsoft argues that AI lowers the time, skill and money needed to discover and exploit weaknesses. Attackers and defenders both gain speed, scale and autonomy from the technology. The company expects defenders to catch up eventually, but it says attackers hold the lead for now.

"While the equilibrium between attackers and defenders will likely ultimately be re-established, in the near term we are in a period where attackers are reaching to advantages first, and defenders will need to move sharply in order to close the gap," Microsoft said.

Discovery outpaces patching

The gap is widest in vulnerability research. AI-assisted discovery turns up flaws faster than organizations can fix them, and Microsoft notes that fixing is slow by nature.

"However, remediation is inherently much slower than discovery, not least because many systems lack robust unit and integration testing and so cannot deploy code changes rapidly," the company warned.

As a result, Microsoft expects a period of several years in which the number of known but unpatched vulnerabilities rises sharply. "Well-prepared and well-funded adversaries may be able to stockpile large numbers of zero-day vulnerabilities discovered through such means," the report states.

The window for patching is shrinking too. Microsoft says the median time between a vulnerability being discovered in the wild and being weaponized is now "well below 24 hours."

From days to minutes

Vulnerability research is only one part of the picture. Attackers also use AI to produce custom malware and to speed up what happens after they get in. Tasks such as exfiltrating data, hunting for secrets and moving laterally across a network can now take minutes instead of days.

AI also lets attackers automate larger sections of an attack chain with little human involvement. Less experienced criminals gain capabilities that used to require more skill, and criminal groups can operate in ways once associated with more sophisticated actors such as state-sponsored hackers.

"For sophisticated actors, AI allows unprecedented speed, scale, and customization, reducing the attack chain from days to seconds," Microsoft explained.

"For less-sophisticated actors, AI-powered scaling makes accessible the sort of attack persistence that was previously the sole domain of intelligence agencies, and the ability to customize attacks, especially social engineering attacks for phishing and fraud, is likely to increase attack success rates."

State hackers put AI to work

According to the report, nation-state groups already use AI in real-world operations for research, malware development, social engineering and other stages of an attack.

Microsoft observed:

  • some Chinese state-sponsored actors using AI tools to look for vulnerabilities and learn how to exploit them, while still relying on phishing and remote access trojans
  • Russian state-sponsored actors using "vibe coding" and AI-generated tooling to speed up and power their attacks
  • North Korean remote IT workers using AI for persona development, social engineering and keeping access to organizations
  • other North Korean actors using AI to create malware and manage attack infrastructure

Some of these hackers have also used agentic workflows and LLM-generated code to deploy malware faster.

This fits earlier reporting on North Korean activity. In January, BleepingComputer reported that the Konni hacking group was using AI-generated PowerShell malware against blockchain developers and engineers. The outlet has also covered North Korean fake IT worker schemes that used AI, including deepfake video, to build believable personas and get hired by Western companies.

Humans still in charge

Despite the speed gains, Microsoft says cyberattacks are not yet fully autonomous. Most real-world campaigns still depend on people to choose targets, make decisions and handle the more complex parts of an operation.

"Most observed campaigns still retain human direction, even as frontier systems demonstrate end-to-end autonomy in labs and early real-world cases," the company said.

Our Take

Microsoft's assessment fits with other recent signs that AI is speeding up exploitation of newly disclosed flaws. If weaponization really happens in under a day, this suggests that monthly or slower patch cycles may no longer be enough for internet-facing systems. The practical lesson for defenders seems to be less about buying AI tools and more about the basics Microsoft itself points to: testing pipelines that let fixes ship quickly.

The point about autonomy deserves a careful reading. Microsoft says most campaigns still have humans steering them, but cases such as the DIVD breach by an autonomous AI agent and Carbonato malware using AI agents suggest the "early real-world cases" it mentions are not hypothetical. It is worth watching whether the predicted pile-up of unpatched vulnerabilities shows up in exploitation data over the coming year, and whether defenders can close the gap as quickly as Microsoft hopes.