⌁AI·CYBER·BRIEF▌
AI Threats7 min read

Microsoft: new flaws are weaponized in under a day — yet 30% of break-ins still start with a user

Microsoft's 2026 Digital Defense Report says AI has pushed time-to-exploit well below 24 hours, yet 30% of intrusions still begin with a user running something.

Microsoft's 2026 Digital Defense Report, published on October 1, 2026, says the median time from a vulnerability being found in the wild to a working attack has fallen "well below 24 hours", while companies typically need 30 to 60 days to fix critical internet-facing flaws. AI is part of the reason, but the report's own data shows most intrusions still start the old way — a user running something, or a stolen login. The practical response is unglamorous: faster patching of exposed systems, phishing-resistant sign-in, and teaching staff never to paste commands they were told to run.

What happened, in plain English

Every year Microsoft publishes the Digital Defense Report, a summary of what its security teams saw across the huge volume of signals its products collect. The 2026 edition's headline is that "AI is changing the physics of cybersecurity".

What that means in practice: when a new software flaw (a CVE, or Common Vulnerabilities and Exposures entry — the public ID number a flaw gets) becomes known, attackers now turn it into a working attack faster than ever. Microsoft puts the median gap at well under a day. Meanwhile, nearly 40,000 CVEs were published in the first half of 2026 alone, putting the year on track to roughly double the previous total. Defenders are being asked to patch more things, faster, with the same number of people.

Think of it like a building where the locksmith now gets a list of every weak lock in the city the same morning the burglars do — but the burglars only need one door, and the locksmith has to visit thousands.

The surprising part is how attackers actually get in. According to Microsoft Defender Experts data in the report, "user execution" — someone opening or running something malicious — was 30% of observed initial access, and "valid accounts" — logging in with real, stolen credentials — another 20%. One trick stood out: ClickFix, where a fake web page tells the visitor to copy a command and paste it into Windows' Run box or a terminal "to fix a problem". Microsoft Defender saw such commands executed on more than 1.1 million unique devices between February and early May 2026, roughly eight times more than before.

AI makes these old tricks faster, more convincing and cheaper to run at scale. It has not replaced them.

Are you affected? What to do now

Every organisation is in scope; this is a landscape report, not a single bug. There is no patch to install. What it gives you is a clear list of priorities. In order:

1. Measure your patch speed for internet-facing systems

  • List everything reachable from the internet: VPNs, firewalls, mail gateways, remote-access tools, web apps.
  • Check how long critical fixes on those systems actually take. If the answer is "weeks", that is now the main gap Microsoft is describing.
  • Agree a fast-track process (hours to a few days) for actively exploited flaws on exposed systems, with pre-approved maintenance windows.

2. Close the oldest doors first

  • Microsoft reports that among detections tied to the five leading CVEs it analysed, 58% were linked to a single flaw from 2020: CVE-2020-1472 ("Zerologon", a Windows domain controller flaw). Confirm every domain controller has been patched and enforcement mode is on.

3. Make stolen passwords less useful

  • Move administrators and high-risk staff to phishing-resistant sign-in (passkeys, FIDO2 security keys, or certificate-based authentication), as the report recommends.
  • Review who has admin rights and remove what is not needed (least privilege).

4. Train against ClickFix specifically

  • Tell staff, in one sentence: no legitimate website, CAPTCHA or helpdesk will ask you to paste a command into Run, PowerShell or Terminal.
  • Helpdesk: treat any user report of "the page told me to run a command" as a possible incident.
  • Where your tools allow, restrict or log use of the Windows Run dialog and PowerShell for standard users, and alert on scripts launched from them.

5. Bring your AI tools into the security programme

  • The report describes a malicious browser extension, found in December 2025, that harvested ChatGPT and DeepSeek conversations from more than 600,000 installs across nearly 10,000 organisations. Audit browser extensions and allow only approved ones.
  • Assume chatbot history may contain source code, customer data or secrets — Microsoft notes it "now routinely" does. Set rules for what may be pasted into AI tools.
  • For AI agents you deploy: give each its own identity, minimal permissions, and a way to revoke its access quickly.

If you already patch exposed systems within days, use phishing-resistant MFA for admins and have warned staff about ClickFix, the report is mostly confirmation that you are on the right track.

The expert view

Strip away the framing and the report makes two claims that are worth separating.

The first is about tempo. "Discovery to weaponization well below 24 hours" is a median across what Microsoft observes, and it matches what other vendors have been reporting all year — including Google's finding on October 1 that AI-discovered vulnerabilities skew heavily toward remote code execution. The mechanism is not mysterious: language models are good at reading a patch diff or an advisory, locating the changed code path, and producing a first working trigger. That collapses the old "patch Tuesday, exploit Wednesday" cycle into hours. Microsoft's own wording is careful — it says remediation "is inherently much slower than discovery", which is an admission that patching alone cannot close the gap. Compensating controls (segmentation, attack-surface reduction, virtual patching at the edge) matter more when the window is this short.

The second claim is about autonomy, and here the report is more measured than some coverage of it. Microsoft describes a progression from AI assisting operators, to AI directing attacks, toward autonomous execution, and says one of its own evaluations chained 32 attack stages in a controlled environment. In its accompanying blog post, Microsoft says threat actors use AI across reconnaissance, social engineering, malware and exploit development, and post-compromise activity, but that usage "remains focused on specific attack workflow components rather than comprehensive integration". In other words: capability demonstrated in the lab, partial adoption in the wild. That is consistent with this year's public incidents, where humans still chose targets and monetised results.

What is genuinely new versus rebranded? The ClickFix figure is the most useful number in the report precisely because it is not new. Pasting a command is social engineering from the 2000s; what changed is volume and polish, which AI helps with. The 2020 Zerologon statistic makes the same point from the other side: attackers with faster tooling still go for the cheapest door.

The report also signals that AI systems are now part of the attack surface, not just a tool. Microsoft lists five risk classes for AI agents — prompt manipulation, sensitive data exposure, identity compromise, excessive agency and operational integrity — and warns that teams must watch for models that "pursue objectives or take actions that diverge from the intent of their operators". After a month of public disclosures about agents behaving outside their brief, that line reads less like speculation and more like an operational requirement.

What remains unknown: the summary pages do not explain how the 24-hour median is calculated, which vulnerabilities are counted, or how much of the speed-up Microsoft attributes to AI versus to the sheer number of disclosed CVEs. Some figures circulating in media coverage (for example on phishing's share of incidents) come from the full PDF, which we could not access directly; we have only used figures we could read on Microsoft's own pages. Several of the AI-agent adoption figures on Microsoft's report page are also given without a stated source.

The takeaway for practitioners is not "AI changes everything". It is that the time budget for doing the basics has shrunk, and the basics now include the AI tools your own staff use every day.

Official sources

Get the daily brief

AI + security signal by email: headlines, a two-line summary, a link. No noise, no spam.

How often