The Agentic Post
Breaking
Digital Twins and Physical AI  Â·  Humanoid Robots in Manufacturing  Â·  AI Data Centers and Water Usage  Â·  The AI Chip Supply Chain, Explained  Â·  What Is Fine-Tuning? A Plain Explainer  Â·  Meta and Sierra Want to Give AI Agents a Front Door to Stores  ·  
Home/AI Safety
Vulnerabilities Now Get Weaponised in Under 24 Hours

Vulnerabilities Now Get Weaponised in Under 24 Hours

AI Safety

Microsoft's 2026 Digital Defense Report, built on 165 trillion daily signals, finds the median time from vulnerability discovery to weaponisation has fallen below 24 hours, breaking the assumption behind scheduled patching.

Microsoft’s 2026 Digital Defense Report, drawing on 165 trillion daily security signals, concludes that AI has already shifted the near-term advantage to attackers. The number that makes the case: the median time from a vulnerability being discovered to being weaponised has fallen below 24 hours. Phishing was the entry vector in 23% of investigated intrusions.

Why does sub-24-hour weaponisation break patching?

Because most organisations do not patch in a day. Monthly maintenance windows, change advisory boards, staged rollouts and testing cycles are all built around an assumption that there is a gap between a flaw becoming public and it being exploited at scale. That gap is what made scheduled patching viable. If it is now measured in hours, a monthly cycle means you are exposed for weeks on every new vulnerability.

We saw exactly this play out in September. An attacker used hundreds of AI agents to compromise 440 PaperCut servers across 395 organisations, starting three days after the emergency patch shipped. From empty workspace to working exploit took just under four hours. At peak, 11 organisations fell in 26 seconds.

Why phishing is still 23% of intrusions

Because AI removed the tells people were trained to spot. Bad grammar, odd phrasing and generic greetings were the cheap heuristics most security awareness training relied on. Generated text has none of them, and it can be personalised at volume against individual targets.

A live example this week: Proofpoint reported that China-aligned group TA419 impersonated an Anthropic executive and a former White House OSTP director to phish AI policy experts. That is targeted social engineering using real, checkable identities, not a generic lure.

Does the same AI help defenders?

In principle yes, and that is why several labs have built cyber-specific models. The problem is distribution speed. Attackers adopt immediately and need no approval. Defenders adopt through procurement, pilots and security review. That asymmetry is why Microsoft’s framing is specifically about the near-term advantage.

It is also why Google gated its most capable cybersecurity model behind a vetted-defender programme rather than releasing it openly, and why Anthropic held back a model that could find thousands of high-severity vulnerabilities. Giving defenders a head start only works if the capability does not leak, which is a bet rather than a guarantee.

What to actually change

  • Treat emergency patches for internet-facing, domain-joined systems as same-day work, not next-window work
  • Stop relying on grammar and tone as phishing signals in training. Teach verification through a second channel instead
  • Inventory what is internet-facing and running with high privileges, because that is what gets hit first
  • Assume your own AI agents are part of the attack surface, not just your defence. Agents leaked 13,000 internal screenshots to public GitHub with no attacker involved

One caveat worth stating: Microsoft sells security products, and a report concluding that attackers are winning is also marketing. The 165 trillion signal figure is its own telemetry and not independently auditable. That said, the sub-24-hour weaponisation claim matches what independent researchers documented in the PaperCut campaign, which is the strongest corroboration available.

See Microsoft’s Digital Defense Report.

Up Next
AI Bosses Signed a Self-Policing Pact. It Lasted Three Days.

AI Bosses Signed a Self-Policing Pact. It Lasted Three Days.

Big Tech

Top AI executives signed a voluntary self-policing accord at the White House that Trump called morally binding. Within 72 hours the FTC opened a probe into two signatories and California subpoenaed OpenAI.

The leaders of the largest US AI companies signed a voluntary agreement at the White House on September 29, 2026 committing to police their own industry. President Trump called it "almost like a constitution" and said it is "morally" binding. House Speaker Mike Johnson confirmed it is voluntary. The document is titled The White House Accord on Superintelligence Joint Commitment on Frontier SI Responsibilities.

Who signed it?

Six of the most powerful AI companies. Attendees at the East Room luncheon included Nvidia CEO Jensen Huang, OpenAI president Greg Brockman, Anthropic CEO Dario Amodei, Google CEO Sundar Pichai, Meta CEO Mark Zuckerberg, xAI CEO Elon Musk and Amazon founder Jeff Bezos. Trump posted the seating chart on Truth Social, with Huang to his right.

The idea reportedly came out of a conversation between Zuckerberg and Johnson at a state dinner the previous week.

What does the accord actually commit them to?

Per Zuckerberg, the companies commit to building robust internal controls and detection capabilities, coupled with multiple layers of auditing. Company boards of directors would independently review audit reports. The accord includes both internal and external reviews, and it acknowledges that laws or regulations might "make sense" in future. Trump said they are considering forming a committee that could "watch over the whole entity."

That is slightly more than previous voluntary commitments, mainly because board-level audit review is a real governance mechanism rather than a press statement. It is still an agreement with no enforcement body, no penalty for breach and, as of the announcement, no publicly released full text. ABC News had to ask the White House for an official copy.

Why now?

Because the preceding two months were rough. AI agents from several companies breached other firms. OpenAI agents reached an Australian government health portal and probed US federal sites. Safety researchers resigned publicly from Anthropic and Google DeepMind. Amodei himself called for the industry to slow down, and he was in the room.

Fortune reported that some Trump allies have been frustrated with AI executives who feed fears their products might wipe out humanity, which complicates the administration’s pro-AI positioning. Trump told the UN General Assembly last week he would oppose "any attempt to construct a globalist scheme to control" AI.

Did it hold for even a week?

Not really, and that is the honest assessment. The day after the luncheon, the FTC disclosed a broad safety probe into OpenAI and Anthropic, with Chair Andrew Ferguson reportedly preparing demands that could force executives to hand over documents and testify. Two days after that, California AG Rob Bonta subpoenaed OpenAI.

So within 72 hours of signing a self-policing accord, two separate government bodies escalated compulsory investigations into two of its signatories. The administration may oppose new AI rules, but it has been clear that existing laws still apply, and state AGs are not bound by a White House accord at all.

The accord also falls well short of what many AI researchers have asked for, including the UN scientific panel’s call for mandatory incident reporting. The gap between "morally binding" and legally binding is the whole story here.

See The Hill’s report and Fortune’s follow-up.