Site navigation

Microsoft Reveals How Quickly AI Is Weaponising Vulnerabilities

Graham Turner

,

AI cyberattacks
Microsoft’s 2026 Digital Defense Report highlights growing risks from autonomous AI agents and increasingly automated attacks.

Microsoft has warned that artificial intelligence is accelerating the pace of cyberattacks, with vulnerabilities increasingly being weaponised faster than organisations can remediate them.

The 2026 Microsoft Digital Defense Report points to a threat environment in which AI is being used across vulnerability discovery, reconnaissance, phishing, malware and exploit development, data analysis and post-compromise activity.

Microsoft said the median time between a vulnerability being discovered in the wild and its weaponisation has fallen to well below 24 hours. By comparison, organisations can take between 30 and 60 days to remediate critical externally facing vulnerabilities, creating what the company described as a widening window of opportunity for attackers.

Nearly 40,000 Common Vulnerabilities and Exposures (CVEs) were published during the first half of 2026 alone, according to Microsoft, as the volume of publicly reported vulnerabilities continues to accelerate.

The company said AI is helping both security researchers and malicious actors identify weaknesses more rapidly, while also allowing parts of the attack process to be automated or carried out at greater scale.

Microsoft Threat Intelligence has observed a progression over the past six months from AI primarily assisting human attackers towards systems directing activity and, increasingly, carrying out parts of attacks autonomously.

While Microsoft stressed that fully autonomous attacks are not yet the norm, it said advanced AI systems are demonstrating an ability to perform increasingly complex operations. In one controlled evaluation cited by the company, a system carried out a 32-stage attack sequence.

The report also highlights the growing use of AI in social engineering and technical attack workflows, where automation can allow campaigns to be tailored more quickly and at significantly greater scale.

Despite the changing technology, however, Microsoft said many of the underlying routes used to compromise organisations remain familiar.

Data from Microsoft Defender Experts found that user execution was responsible for 30% of observed initial access, while valid accounts accounted for a further 20%.

The company said attackers continue to target trusted software, identities, developer workflows, applications and services, with AI potentially making those existing weaknesses easier to identify and exploit.

Microsoft also pointed to the rapid growth of ClickFix attacks, which attempt to convince users to execute malicious commands themselves.

Between February and early May 2026, Microsoft Defender detected attacker-supplied ClickFix commands being executed on more than 1.1 million unique devices, representing an increase of roughly eightfold.

Legacy vulnerabilities also remain a significant source of risk. Among detections linked to the five leading CVEs examined by Microsoft, 58% related to a single vulnerability first disclosed in 2020.

The findings suggest that while emerging AI-enabled attacks are increasing pressure on security teams, failures to address established vulnerabilities, identity risks and excessive permissions continue to provide attackers with opportunities.

AI Agents Expand Enterprise Attack Surface

Microsoft also highlighted the growing security implications of AI agents as they become more deeply embedded within enterprise environments.

Agents can be given access to company data, applications, APIs and other tools, with varying degrees of autonomy. Microsoft said organisations therefore need to consider not only the security of the underlying AI model but also the identities, permissions, infrastructure and data connected to it.

Areas highlighted in the report include agent identity, access controls, authentication between agents, attribution and the ability to revoke access, alongside AI-specific risks such as prompt injection and the security of agent memory and underlying models.

Greater autonomy could also introduce the risk of model misalignment, according to Microsoft, where an AI system takes actions that diverge from the intentions of its operator. The issue could become more significant as agents are granted broader access and permission to act independently.

At the same time, Microsoft said AI could give defenders tools to respond to the same acceleration in attacker capabilities.

Security teams are increasingly able to automate repeatable tasks, correlate information from different systems and use AI to assist with vulnerability discovery, investigation and threat detection.

Microsoft argued that signals from endpoints, identities, cloud environments, applications, email, networks and threat intelligence become more useful when analysed together, particularly where malicious activity spans multiple systems and would otherwise appear fragmented.


Recommended reading


However, the company cautioned that simply giving security teams more information will not necessarily improve their ability to respond.

Instead, Microsoft said organisations need to close the gap between intelligence and action, particularly as AI reduces the time available to identify and contain emerging threats.

The report recommends that organisations continue to focus on established security principles including identity management, least privilege, data protection, exposure management, monitoring and secure software development, while extending those controls to AI systems and agents.

Microsoft said the growing speed, automation and interconnectedness of cyber activity means security increasingly needs to operate continuously rather than as a series of isolated responses to individual incidents.

The company concluded that organisations will need to strengthen their existing security foundations, secure AI systems as they are introduced and increasingly use AI within their own defensive operations if they are to keep pace with faster-moving threats.

Graham Turner

Sub Editor

Latest News

AI Cybersecurity Editor's Picks Security

Microsoft Reveals How Quickly AI Is Weaponising Vulnerabilities

Business Featured

Deputy FM Highlights £32BN Opportunity for South of Scotland

Events Technology

Socitm Conference to Explore AI, Data and Cyber

AI Cybersecurity

AI Finds Higher Risk Vulnerabilities and Leads to More Exploits