Microsoft says threat actors are ahead in the early AI race

Artificial intelligence is revolutionizing cybersecurity, but it’s not all about gaining an edge for defenders. According to Microsoft’s 2026 Digital Defense Report, threat actors are currently outpacing defenders in their adoption and use of AI-powered tools. This has significant implications for organizations worldwide, as attackers can now discover vulnerabilities faster, develop malware more quickly, and operate with greater autonomy.

The report highlights how AI is reducing the time, expertise, and cost required to discover and exploit weaknesses in systems. Attackers are leveraging this advantage to speed up vulnerability research, malware development, and post-compromise activities such as data exfiltration and lateral movement. In some cases, attackers can now automate larger portions of an attack chain with minimal human intervention, making them more efficient and effective.

Microsoft notes that the median time between vulnerability discovery in the wild and weaponization has fallen to well below 24 hours, leaving organizations with a narrow window to patch exposed systems before they are exploited. This creates a perfect storm for attackers, who can now stockpile zero-day vulnerabilities and use AI-generated malware to customize their attacks.

The company also points out that nation-state threat actors have already started using AI in real-world operations, leveraging it to speed up research, malware development, social engineering, and other aspects of an attack. Chinese state-sponsored actors are using AI tools to search for vulnerabilities and learn how to exploit them, while still relying on phishing and remote access trojans. Russian state-sponsored threat actors have been seen using “vibe coding” and AI-generated tooling to accelerate their attacks.

Meanwhile, North Korean threat actors are using AI for persona development, social engineering, and maintaining access to organizations. Some of these hackers have also used agentic workflows and LLM-generated code to accelerate malware deployment, echoing previous campaigns reported by BleepingComputer.

While Microsoft believes that defenders will eventually gain similar benefits from AI, the company acknowledges that attackers currently hold the upper hand. In the near term, defenders need to move swiftly to close the gap and stay ahead of emerging threats. This requires a multifaceted approach, including investing in AI-powered security tools, improving vulnerability remediation processes, and enhancing cybersecurity training and awareness programs.

For organizations, this means being proactive in patching vulnerabilities, implementing robust unit and integration testing, and regularly reviewing their incident response plans. It also highlights the need for greater collaboration between defenders, as well as a more comprehensive understanding of AI’s role in both offense and defense. By acknowledging the current state of play and taking steps to address these challenges, organizations can better prepare themselves for the evolving threat landscape.


Source: Bleeping Computer — 2026-10-01