Home / News EN / Microsoft Digital Defense Report 2026: AI favors attackers in short term

Microsoft Digital Defense Report 2026: AI favors attackers in short term

AI favors attackers. The annual Microsoft Threat Intelligence report, the Digital Defense Report 2026, describes a landscape of faster and more automated cyberattacks, with particular attention to identity as the main objective. The indicated solution is continuous exposure management, surpassing traditional periodic approaches.

AI favors attackers

According to the document, artificial intelligence is modifying the balance between attack and defense, offering an advantage to attackers in the short period. For the most sophisticated operators, the attack chain has been reduced from days to seconds.

AI favors attackers: why it matters

The executive summary of the report lists several uses of AI: vulnerability research, creation of customized malware, acceleration of lateral movement and data exfiltration phases, up to full management of attack chains. AI is also employed to expand the scope of phishing and social engineering attacks, which previously required a manual approach.

Microsoft predicts that these capabilities will become common within one year. The report highlights how the balance between attack and defense will be restored over time, but emphasizes the need for defenders to close the current gap.

Terrell Cox, CVP and Deputy CISO of Microsoft’s Customer Security Management Office, clarifies that the use of AI is currently concentrated on single phases of existing attacks, maintaining fundamental methods already known. The techniques do not change, but increase in scale and speed.

73.3% of initial access attempts exploit user execution, via valid accounts obtained through social engineering and phishing. More than half of intrusions lead to further credential thefts, and 63% involve data theft.

Among the most widespread tools are AiTM (adversary-in-the-middle) phishing kits, which intercept credentials and authenticated sessions, and OAuth application abuse. The time window between vulnerability disclosure and its exploitation has shrunk, often to a few days, making monthly or weekly update cycles inadequate.

What changes and what are the effects

The report therefore suggests transforming threat and vulnerability management (TVM) from periodic activity to a continuous and integrated discipline. Metrics should focus on reducing exposure, detection coverage, and mitigation times.

Among the ten priorities indicated in the report are passkeys and phishing-resistant multi-factor authentication, management of human and non-human identities, visibility on AI tools and agents, rapid patching of perimeter devices, and assume-breach tests (simulations starting from the hypothesis of an already occurred compromise). Company executives are advised to monitor data such as patch installation delays and agent permissions.

The insights offered by the report are also relevant in relation to compliance with the NIS2 directive. The deadline to make operational the basic security measures set by ACN (determination 379907/2025) for entities included in the NIS list in 2025 expires on October 31, 2026. For those who entered the perimeter during 2026, the deadline is July 31, 2027. After the expiration, the Agency may initiate verifications.

Source and further reading on AI favors attackers: original article.

* Content created with the assistance of artificial intelligence systems.