Skip to main content
Threat IntelligenceEmerging Threats

AI Gives Threat Actors Edge in Cyberwar

A laptop screen glows on a minimalist table in a bright, empty tech research facility.
"While the equilibrium between attackers and defenders will likely ultimately be re-established, in the near term we are in a period where attackers are reaching to advantages first, and defenders will need to move sharply in order to close the gap," says Microsoft.

AI is speeding discovery faster than patching

Microsoft's 2026 Digital Defense Report warns that artificial intelligence is reducing the time, expertise, and cost required to discover and exploit software weaknesses. The company says vulnerability research driven by AI is increasingly outpacing defenders' ability to remediate flaws. Microsoft highlights a structural problem: remediation is inherently slower than discovery, "not least because many systems lack robust unit and integration testing and so cannot deploy code changes rapidly," a constraint that will make known-but-unpatched vulnerabilities spike for a multi-year period.

Weaponization now measured in hours, not days

The report states that the median time between vulnerability discovery in the wild and weaponization has fallen "well below 24 hours." That compression of time further reduces the window organizations have to patch exposed systems before those flaws are turned into exploits — and, Microsoft warns, well‑prepared and well‑funded adversaries may be able to stockpile large numbers of zero-day vulnerabilities discovered through AI-accelerated means.

Customized malware and faster post‑compromise activity

Microsoft says attackers are using AI to generate customized malware and to accelerate post-compromise activities such as data exfiltration, secret discovery, and lateral movement, reducing those actions "from days to minutes." The company adds that AI can automate larger portions of an attack chain with limited human intervention, and that it gives less-experienced cybercriminals access to capabilities that previously required more skill. "For sophisticated actors, AI allows unprecedented speed, scale, and customization, reducing the attack chain from days to seconds," Microsoft writes. "For less-sophisticated actors, AI-powered scaling makes accessible the sort of attack persistence that was previously the sole domain of intelligence agencies."

Nation-state actors are adopting AI in real operations

Microsoft reports that nation-state threat actors have already begun using AI in real-world operations. The company says some Chinese state-sponsored actors are using AI tools to search for vulnerabilities and learn how to exploit them while continuing to rely on phishing and remote access trojans. Russian state-sponsored actors have been observed using "vibe coding" and AI-generated tooling to speed and power attacks. Microsoft also identifies North Korean activity: remote IT workers linked to North Korea are reportedly using AI for persona development, social engineering, and maintaining access, while other North Korean actors use AI to create malware and manage attack infrastructure.

Agentic workflows, LLM code, and human direction

Microsoft notes that some threat actors have used agentic workflows and LLM-generated code to accelerate malware deployment, and that several campaigns match previously reported North Korean state-linked activity. The company is careful to add that cyberattacks have not yet become fully autonomous: "Most observed campaigns still retain human direction, even as frontier systems demonstrate end-to-end autonomy in labs and early real-world cases," Microsoft says.

What this means for technologists, policymakers, and enterprises

  • Technologists and security teams: Expect discovery to continue outpacing remediation and plan for shorter patch windows; the report underscores the need to address testing and deployment bottlenecks that slow fixes.
  • Policymakers and regulators: Microsoft’s findings suggest a multi-year increase in known but unpatched vulnerabilities and the potential for zero-day stockpiles, framing regulatory and procurement conversations around disclosure timelines, incident reporting, and software testing requirements.
  • Enterprises and procurement leaders: The acceleration of weaponization and the availability of AI-generated tooling to less-skilled actors mean organizations should reassess threat models, update incident response plans for faster compromise timelines, and prioritize reducing deployment friction for security updates.

Microsoft’s assessment draws a sharp line: AI is not just an amplifier for well-resourced actors but a force that lowers the bar across the threat spectrum, compresses time-to-exploit into hours or minutes, and exposes long-standing operational weaknesses in patching and testing. The company concludes that defenders will likely catch up, but only if they move sharply to close the gap — a demand that frames the coming years of both offensive innovation and defensive adaptation.

Source: Microsoft says threat actors are ahead in the early AI race — BleepingComputer