Microsoft’s 2026 Digital Defense Report, drawing on 165 trillion daily security signals, concludes that AI has already shifted the near-term advantage to attackers. The number that makes the case: the median time from a vulnerability being discovered to being weaponised has fallen below 24 hours. Phishing was the entry vector in 23% of investigated intrusions.
Why does sub-24-hour weaponisation break patching?
Because most organisations do not patch in a day. Monthly maintenance windows, change advisory boards, staged rollouts and testing cycles are all built around an assumption that there is a gap between a flaw becoming public and it being exploited at scale. That gap is what made scheduled patching viable. If it is now measured in hours, a monthly cycle means you are exposed for weeks on every new vulnerability.
We saw exactly this play out in September. An attacker used hundreds of AI agents to compromise 440 PaperCut servers across 395 organisations, starting three days after the emergency patch shipped. From empty workspace to working exploit took just under four hours. At peak, 11 organisations fell in 26 seconds.
Why phishing is still 23% of intrusions
Because AI removed the tells people were trained to spot. Bad grammar, odd phrasing and generic greetings were the cheap heuristics most security awareness training relied on. Generated text has none of them, and it can be personalised at volume against individual targets.
A live example this week: Proofpoint reported that China-aligned group TA419 impersonated an Anthropic executive and a former White House OSTP director to phish AI policy experts. That is targeted social engineering using real, checkable identities, not a generic lure.
Does the same AI help defenders?
In principle yes, and that is why several labs have built cyber-specific models. The problem is distribution speed. Attackers adopt immediately and need no approval. Defenders adopt through procurement, pilots and security review. That asymmetry is why Microsoft’s framing is specifically about the near-term advantage.
It is also why Google gated its most capable cybersecurity model behind a vetted-defender programme rather than releasing it openly, and why Anthropic held back a model that could find thousands of high-severity vulnerabilities. Giving defenders a head start only works if the capability does not leak, which is a bet rather than a guarantee.
What to actually change
- Treat emergency patches for internet-facing, domain-joined systems as same-day work, not next-window work
- Stop relying on grammar and tone as phishing signals in training. Teach verification through a second channel instead
- Inventory what is internet-facing and running with high privileges, because that is what gets hit first
- Assume your own AI agents are part of the attack surface, not just your defence. Agents leaked 13,000 internal screenshots to public GitHub with no attacker involved
One caveat worth stating: Microsoft sells security products, and a report concluding that attackers are winning is also marketing. The 165 trillion signal figure is its own telemetry and not independently auditable. That said, the sub-24-hour weaponisation claim matches what independent researchers documented in the PaperCut campaign, which is the strongest corroboration available.




