Attackers weaponise flaws in under a day while patching takes up to two months, Microsoft report finds
Attackers now turn newly discovered software vulnerabilities into working exploits in a median time of well under 24 hours. Enterprises typically take 30 to 60 days to fix critical external flaws, according to Microsoft’s 2026 Digital Defense Report. The report covers July 2025 to June 2026 and draws on more than 165 trillion security signals a day. Nearly 40,000 Common Vulnerabilities and Exposures (CVEs) were published in the first half of 2026 alone, and Microsoft expects the full-year total to reach about 72,000, roughly double the 2025 figure.
“AI is changing the physics of cybersecurity. It is reducing the time, expertise, and cost required to discover and exploit weaknesses while enabling both threat actors and defenders to operate with greater speed, scale, and autonomy,” the report states.
Government agencies accounted for 27% of observed threat activity in 2026, up from 17% in 2025, making the public sector the most affected sector in Microsoft’s data. The figure comes from a Microsoft Security blog by Terrell Cox, Corporate Vice President and Deputy CISO, published alongside the report on 1 October.
Ransomware no longer needs an operator
In early July 2026, Microsoft documented what it describes as the first fully automated ransomware extortion attack, which it tracks as JADEPUFFER. According to the report, AI-orchestrated systems identified targets, delivered ransom demands and managed the extortion workflow with minimal human involvement. In a separate controlled evaluation, frontier AI models chained 32 consecutive attack steps against an emulated enterprise environment and achieved full domain compromise.
“AI enables attackers to launch larger-scale campaigns, craft highly convincing personalised phishing attempts, and automate processes that previously required significant manual resources,” the report notes. Microsoft also found that attackers’ use of AI remains “focused on specific parts of existing attack workflows”, including reconnaissance, social engineering, malware and exploit development, and post-compromise activity.
State-backed clusters linked to China, Russia, North Korea and Iran have all built AI into their operations, according to TechTimes’ reporting on the report.
User execution accounted for 30% of observed initial access, ahead of valid accounts at 20%. One of the fastest-growing techniques, ClickFix, tricks people into copying and pasting malicious commands onto their own devices. ClickFix-style commands were run on 1.1 million unique devices between February and early May 2026, an eightfold increase. Malware followed in 96.3% of observed malicious copy-and-paste intrusions, according to OffSeq’s analysis of the report.
In 52.2% of intrusions that used valid accounts, attackers went on to steal more credentials, and 18.4% involved active password spraying. Microsoft also detected more than 46 million attacks impersonating businesses over twelve months.
Password attacks fell 26% year on year, and global ransomware incidents dropped 3%, from 8,749 to 8,521, according to Calcalist. Attackers have moved towards methods that bypass passwords entirely: adversary-in-the-middle phishing and token theft more than doubled in the first half of 2026.
Exposure rises with digital ambition
Customers in the United States accounted for 25.5% of those impacted by cyber activity in Microsoft’s data. Israel followed at 7.6%, then Ukraine at 4.8%, Taiwan at 3.9% and the United Kingdom at 3.8%. The UAE ranked sixth globally at 2.8% and second across the Middle East and Africa, ahead of India and Japan at 2.5% each, Canada at 1.8% and Germany at 1.7%. Within Iranian threat activity, Israel was the target of 39%, the United States 23% and the UAE 9%, Calcalist reported.
“The UAE is entering a phase in which AI is becoming part of the operating model of government and business. Cybersecurity therefore cannot be treated as a separate layer added after transformation takes place,” said Yazan Khasawneh, Director of Cyber Security at Microsoft UAE.
Microsoft, the UAE Cyber Security Council and Core42 plan to deploy MDASH, Microsoft’s AI-powered cybersecurity capability, across UAE government entities. The collaboration aims to help security teams identify vulnerabilities, prioritise risk and respond to emerging threats faster and at greater scale, while meeting sovereign security, privacy and operational-resilience requirements. With the public sector now taking more than a quarter of observed attacks worldwide, the deployment shows how governments are starting to buy AI-driven defence at national scale.
“It has to be designed into the way organisations adopt AI, manage identities, protect data and maintain continuity from the outset. The latest Digital Defense Report shows why this matters: threats are moving faster and becoming more interconnected,” Khasawneh added.
One compromise now spreads across borders
“Threat activity can span infrastructure, identities, applications, cloud environments, and software supply chains,” the report states. According to Microsoft, one compromised identity, supplier, platform or service provider can create consequences across organisations, sectors and borders.
Exposed cloud workloads were attacked within 5.3 hours on average, and more than half of compromised containers were exploited within 24 hours. Older flaws remain a risk: one 2020 vulnerability, CVE-2020-1472, accounted for 58% of detections tied to the five leading CVEs Microsoft analysed.
The report also adds AI agents to the list of things to secure. It examines agent identity, appropriate access, authentication between agents, attribution and the ability to revoke access, as well as prompt injection, memory, models and data.
Microsoft recommends that organisations focus on three priorities: protecting identities, responding faster and building resilience. In practice, that means stronger authentication, less reliance on passwords, faster detection and response, regular incident-response exercises, and systems designed so critical operations can continue through disruption. The report also calls for access controls to extend to AI systems and agents, and for exposure management to run continuously.
“Our focus is to help organisations build the security and resilience they need to innovate with confidence,” Khasawneh said. For any organisation, the report’s central numbers leave little margin: if a flaw can be exploited within a day and takes up to two months to fix, attackers have a window of several weeks. Across the 1.1 million devices hit by ClickFix, the person who pasted the command was usually the first line of defence and the last.