
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace.
This comes from Microsoft's 2026 Digital Defense Report, which strongly focuses on how artificial intelligence is changing both offensive and defensive cybersecurity operations.
Microsoft says AI is reducing the time, expertise, and cost required to discover and exploit weaknesses, while allowing attackers and defenders alike to operate with greater speed, scale, and autonomy.
However, while the company believes defenders will eventually gain similar benefits from the technology, it says attackers currently have the advantage.
"While the equilibrium between attackers and defenders will likely ultimately be re-established, in the near term we are in a period where attackers are reaching to advantages first, and defenders will need to move sharply in order to close the gap," says Microsoft.
Microsoft says this is particularly true in vulnerability research, where AI-powered discovery is increasingly outpacing defenders' ability to remediate flaws.
"However, remediation is inherently much slower than discovery, not least because many systems lack robust unit and integration testing and so cannot deploy code changes rapidly," warns Microsoft.
"This means the world is likely to experience a multi-year period where the number of known but unpatched vulnerabilities spikes. Well-prepared and well-funded adversaries may be able to stockpile large numbers of zero-day vulnerabilities discovered through such means."
Microsoft also says the median time between vulnerability discovery in the wild and weaponization has fallen "well below 24 hours," further limiting the time organizations have to patch exposed systems before they are exploited.
In addition to vulnerability research, attackers are using AI to generate customized malware and accelerate post-compromise activities such as data exfiltration, secret discovery, and lateral movement from days to minutes.
Microsoft says AI can also help threat actors automate larger portions of an attack chain with limited human intervention, while giving less experienced cybercriminals access to capabilities that previously required more skill.
The company also says AI can also give criminal groups capabilities once associated with more sophisticated threat actors, like state-sponsored hackers.
"For sophisticated actors, AI allows unprecedented speed, scale, and customization, reducing the attack chain from days to seconds," explains Microsoft.
"For less-sophisticated actors, AI-powered scaling makes accessible the sort of attack persistence that was previously the sole domain of intelligence agencies, and the ability to customize attacks, especially social engineering attacks for phishing and fraud, is likely to increase attack success rates."
AI becomes a tool for state-sponsored hackers
Microsoft says nation-state threat actors have already started to use AI in real-world operations, using it to speed up research, malware development, social engineering, and other parts of an attack.
Some Chinese state-sponsored actors now use AI tools to search for vulnerabilities and learn how to exploit them, while still relying on phishing and remote access trojans.
Microsoft has also seen Russian state-sponsored threat actors using "vibe coding" and AI-generated tooling to speed up and power their attacks.
According to Microsoft, North Korean remote IT workers are using AI for persona development, social engineering, and maintaining access to organizations. Other North Korean threat actors use it to create malware and manage attack infrastructure.
Microsoft says some of these hackers have also used agentic workflows and LLM-generated code to accelerate malware deployment.
Those campaigns are similar to those previously reported North Korean state-linked campaigns.
In January, BleepingComputer reported that the North Korean Konni hacking group was using AI-generated PowerShell malware to target blockchain developers and engineers.
BleepingComputer has also reported on North Korean fake IT worker operations that used AI, including deepfake video, to create convincing personas and get hired by Western companies.
While AI has become a powerful tool for speeding up the creation and conducting of attacks, Microsoft cautions that cyberattacks have not yet become fully autonomous.
The company says most real-world campaigns still rely on humans to select targets, make decisions, and handle complex parts of an attack.
"Most observed campaigns still retain human direction, even as frontier systems demonstrate end-to-end autonomy in labs and early real-world cases," says Microsoft.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat