Artificial intelligence is accelerating parts of the cyberattack cycle to the point that tasks that previously took days can be executed in seconds. The assessment was released by Microsoft this Thursday (1st) in Microsoft Digital Defense Report 2026, which points to a combination of greater automation, speed, and autonomy in the operations of malicious groups.
The company says it already observes AI being used in vulnerability discovery, target reconnaissance, phishing, malware and exploit development, data analysis, and post-intrusion activities. In controlled tests, advanced systems managed to chain up to 32 stages of an attack, while AI-orchestrated operations have also begun to appear in real environments.
Microsoft stresses, however, that complex fully autonomous attacks are still not the norm. Most sophisticated intrusions still depend on significant human direction, but activities that required time and specialized knowledge can be accelerated, repeated, or delegated to AI systems.
Flaws can be turned into attacks in less than 24 hours
The report points out that the median time between the discovery of a vulnerability in a real-world environment and its transformation into a tool usable in attacks has fallen to well under 24 hours. At the same time, companies can take between 30 and 60 days to fix critical vulnerabilities exposed to the internet.
This gap widens the period in which systems remain vulnerable after the disclosure or discovery of a flaw. In the first half of 2026 alone, nearly 40,000 CVE vulnerabilities were published, according to Microsoft.
The pressure does not come only from new flaws. Data from the report show that traditional techniques remain relevant: execution of actions by the user themselves accounted for 30% of observed initial accesses, while compromised valid accounts accounted for another 20%. Between February and early May, commands associated with the ClickFix technique were executed on more than 1.1 million unique devices.
The survey also shows how the window for reaction is already short in connected environments. Exposed cloud workloads took, on average, 5.3 hours to suffer an attempted attack, while 63% of the analyzed intrusions involved data theft.
Microsoft says that the same technology that accelerates attackers can also be used in defense, automating risk discovery, signal correlation, investigation, and response. For the company, the challenge becomes reducing the interval between identifying a threat and defensive action, as both sides move toward machine-speed operations.



