Microsoft: AI Gives Cyberattackers an Advantage Over Defenders
Cyberattackers are using artificial intelligence to discover vulnerabilities, develop malware, and automate post-breach activity faster than security teams can respond, according to Microsoft’s 2026 Digital Defense Report.
The report examines how AI is transforming both offensive and defensive cybersecurity operations. Microsoft says AI reduces the time, expertise, and cost required to find and exploit weaknesses, allowing attackers and defenders to operate faster, at greater scale, and with more autonomy.
However, Microsoft believes attackers currently have the advantage.
“Although the balance between attackers and defenders will likely be re-established eventually, in the short term we are in a period where attackers gain the upper hand first, and defenders will need to move rapidly to close the gap,” Microsoft said.
AI-powered vulnerability discovery is outpacing remediation
Microsoft says the gap is especially concerning in vulnerability research, where AI-powered discovery is increasingly outpacing defenders’ ability to remediate flaws.
“However, remediation inherently takes much longer than detection because many systems lack robust unit and integration tests and code changes cannot be deployed quickly,” Microsoft warns.
As a result, the company expects a multi-year increase in known but unpatched vulnerabilities. Well-prepared and well-funded adversaries could potentially stockpile large numbers of zero-day vulnerabilities discovered with the help of AI.
Microsoft also reports that the median time between vulnerability discovery and weaponization is “well under 24 hours.” This leaves organizations with very little time to patch exposed systems before attackers begin exploiting them.
AI accelerates malware development and post-breach attacks
Attackers are using AI to create customized malware and accelerate post-compromise activities, including data exfiltration, secret discovery, and lateral movement. Tasks that once took days can potentially be completed in minutes.
AI can also reduce the need for human intervention and automate significant portions of the attack chain. Microsoft says this gives inexperienced cybercriminals access to capabilities that previously required more advanced expertise.
The technology could also empower criminal groups associated with more sophisticated threat actors, including state-sponsored hackers.
“For advanced attackers, AI enables unprecedented speed, scale, and customization, reducing attack chains from days to seconds,” Microsoft explains.
“For less sophisticated attackers, AI-powered scaling enables attack persistence that was previously the exclusive domain of intelligence agencies, and the ability to customize attacks, especially social engineering attacks for phishing and fraud, can increase attack success rates.”
State-sponsored hackers are already using AI
According to Microsoft, nation-state threat actors have begun using AI in real-world operations to accelerate research, malware development, social engineering, and other stages of cyberattacks.
Some Chinese government-backed attackers are using AI tools to search for vulnerabilities and learn how to exploit them, while also relying on phishing and remote access Trojans.
Microsoft also confirmed that Russian state-sponsored attackers are using “vibe coding” and AI-generated tools to improve and accelerate their operations.
North Korean threat actors are using AI to develop personas, conduct social engineering, and maintain access to targeted organizations, according to Microsoft. Remote IT workers linked to North Korea are also using AI for persona development. Other North Korean hackers use the technology to create malware and manage attack infrastructure.
Some of these threat actors are also using agent workflows and code generated by large language models to accelerate malware deployment.
These activities resemble previously reported North Korean campaigns. In January, BleepingComputer reported that North Korea’s Konni hacking group was targeting blockchain developers and engineers with AI-generated PowerShell malware.
BleepingComputer also reported on North Korean fake IT workers who used AI, including deepfake videos, to create convincing personas and secure employment at Western companies.
Cyberattacks are not fully autonomous yet
Although AI is becoming a powerful tool for speeding up the creation and execution of attacks, Microsoft says cyberattacks are not yet fully autonomous.
Most real-world campaigns still depend on human operators to select targets, make decisions, and manage the complexities of an attack.
“Even though Frontier systems have demonstrated end-to-end autonomy in the lab and in early real-world cases, most observed campaigns still retain human direction,” Microsoft said.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



