Microsoft Digital Defense Report 2026: the numbers to act on
The Microsoft Digital Defense Report 2026 says AI gives attackers the early edge. These are the numbers that change what you patch and turn on this month.
Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

The Microsoft Digital Defense Report 2026, published on October 1, says attackers are getting more out of AI than defenders right now, and that the gap shows up as speed. Microsoft's headline number is that the median time from a vulnerability being found in the wild to being weaponized is now "well below 24 hours." The report also says phishing started far more of the intrusions its responders handled, and that paste-a-command scams spiked again between February and May. Most of what it asks you to do is not new: patch faster, move to passkeys, and stop trusting anything that tells you to run a command.
Key takeaways
- Speed: Microsoft says the median time from discovery in the wild to a working exploit has fallen "well below 24 hours," and it now tells organizations to fix internet-facing and identity systems within 72 hours.
- Phishing: in Microsoft's incident response cases, 23% of intrusions began with phishing, up from 7% a year earlier. The most common technique steals your signed-in session, which defeats one-time codes.
- ClickFix: Microsoft Defender saw people paste attacker commands on more than 1.1 million devices between February and early May 2026, about eight times more than at the start of that window.
- AI attacks: Microsoft names Chinese, Russian and North Korean state actors using AI for vulnerability research, tooling and social engineering, and cites the first documented automated ransomware attack. It also says most real intrusions still have humans steering them.
- Caveat: this is Microsoft's report about Microsoft's own telemetry and customers. It is a large view of the threat landscape, not an independent audit, and Microsoft sells the defenses it recommends.
What the Microsoft Digital Defense Report 2026 measures
The full report is a 103-page PDF covering July 2025 through June 2026, compared against July 2024 through June 2025. Its data comes from Microsoft's own products and services: the company says it processes more than 165 trillion security signals a day and screens 5.2 billion emails a day. The report's landing page links the PDF and an executive summary.
That vantage point is huge, but it has edges. The numbers describe Microsoft's customers, incident response cases and detections, and different charts use different datasets, so two phishing percentages in the same report can disagree. We name the dataset behind each figure below.
In its launch post, Microsoft's Terrell Cox frames the year as one where threat actors are adding AI to reconnaissance, social engineering, malware and exploit development, and post-compromise work, while their use stays "focused on specific parts of existing attack workflows."
Bugs now become attacks in under a day
The number that should change your patch schedule is on page 14. Microsoft says vulnerability discovery and weaponization have gone from needing human experts to, in many cases, "simply writing a prompt," and that the median time from discovery in the wild to weaponization is now well below 24 hours. It also estimates a record of about 72,000 CVEs (publicly catalogued vulnerabilities) tracked for 2026.
Microsoft's Red Team explains why: every fix points to the flaw it closes, and AI makes it faster to turn a patch back into an exploit. So patch velocity, not patch availability, is the control that matters.
The report's own recommendation is concrete. Fix newly identified vulnerabilities that affect an internet-facing or identity system within 72 hours. Microsoft contrasts that with a median of 30 to 60 days for enterprises to remediate critical external CVEs, and says traditional monthly patch cycles "may no longer be fast enough" for those systems.
There's a twist that matters for small teams. When Microsoft looked at which vulnerabilities its Defender alerts tied to exploitation attempts, the top one was CVE-2020-1472, the Netlogon flaw from 2020, at 58% of those detections. The rest of the top five were also years old. Microsoft notes that detections are not confirmed exploitation, but the pattern is clear: fast new exploits are a threat, and so are old ones nobody patched.
Phishing is back as a front door
In Microsoft's incident response findings, phishing was the way in for 23% of intrusions in the 2026 period, up from 7% the year before. Exploitation of public-facing applications also rose, from 15% to 24%. BleepingComputer's coverage led with the AI angle; the phishing jump is the figure most people can act on today.

What kind of phishing matters too. Microsoft says adversary-in-the-middle (AiTM) phishing, where a fake page relays your login to the real site and grabs the session cookie, now makes up 44.6% of the phishing techniques it identified. Because the attacker steals the signed-in session, a code from an authenticator app or a text message doesn't stop it.
Microsoft's answer is passkeys. The report explains that a passkey only works on the site or app it was created for, so it won't sign you in to a lookalike page. It also says password attacks fell 26% year over year, which it reads as evidence that MFA and passkeys are pushing attackers toward other methods, AiTM included.
Paste-a-command scams surged again
ClickFix is the trick where a fake CAPTCHA or error message tells you to paste a command into Windows Run, Terminal or PowerShell. Microsoft says it saw this kind of user-pasted command run on more than 1.1 million unique devices between February and early May 2026, roughly an eightfold increase, which it links to ClickFix kits sold as a service. Weekly volume went from about 38,000 devices in the first week of February to about 310,000 in the first week of May.
The report also flags a "FileFix" variant that asks you to paste the command into the File Explorer address bar instead. We covered a live example on October 2: a fake ChatGPT GPT that led to a ClickFix page and installed a remote access trojan.
Voice calls are the other growth area. Microsoft says confirmed malicious voice phishing over cross-tenant Microsoft Teams calls rose 502% from a year earlier, with attackers often talking targets into installing a remote support tool.
AI-driven attacks: what is shown and what isn't
On state actors, the report gives specific examples. Some Chinese actors use AI tools to search for vulnerabilities or tips on exploiting them. Microsoft identified Russian actors using vibe coding or AI-generated tooling, though it says AI is a force multiplier for Russia rather than a change in method. North Korean actors use AI for persona development, social engineering and sustained access, and some experimented with agentic workflows to speed up malware deployment. Microsoft expects all four main state actors, China, Iran, North Korea and Russia, to keep folding AI into their operations; its Iran section doesn't describe a specific AI use.
On autonomy, Microsoft cites what the Sysdig Threat Research Team assessed as the first documented case of agentic ransomware, an extortion operation in early July 2026 that Sysdig named JADEPUFFER. Microsoft says it has observed AI-orchestrated intrusions sharing elements with that activity, that volumes remain low, and that initial access has consistently come from internet-exposed services running known-vulnerable software. That is an old door, opened faster.
In a lab test, Microsoft adds, two frontier models fully compromised a mock company network with no defenders in it, without human help.
Here's what the report does not show. It does not say AI-run attacks are common: Microsoft writes that in most real-world operations it observes, complex intrusions "still retain meaningful human direction." And it doesn't put a number on how many of the phishing intrusions above used AI-written lures, so the 7% to 23% jump is not, on the report's own evidence, an AI statistic. What it does claim is speed: AI is cutting post-compromise steps like secret discovery and lateral movement from days to minutes.
What it means for you
If you're a regular user, three habits cover most of what the report describes:
- Turn on passkeys wherever your important accounts offer them, starting with email and your Microsoft, Google or Apple account. They resist the AiTM phishing that beats codes.
- Never paste a command because a website, CAPTCHA, video or "fix" told you to. No legitimate check works that way.
- Install updates the day they arrive on your phone, computer and router, and be suspicious of any unexpected support call, including one on Teams.
If you run IT for a small business, the report's own recommendations translate into a short list:
- Patch anything internet-facing or tied to identity (VPNs, firewalls, remote access, SharePoint, Exchange) within 72 hours of a fix, and check you're not still exposed to old ones like Netlogon.
- Keep an inventory of external systems and remote tools, and isolate whatever can't be patched.
- Move admins and then everyone else to phishing-resistant sign-in, and have a playbook to revoke sessions and reset credentials fast.
- After a new flaw is disclosed in something you run, Microsoft suggests reviewing the previous 90 days for signs it was used before you patched.
- Treat AI agents and AI coding tools as software with credentials. The report says Microsoft treats self-hosted agent platforms as untrusted code, fit only for isolated hosts with low privileges. Our look at AI agents asking for Full Disk Access on macOS covers the same question on a personal computer.
More security coverage lives in our software section.
Bottom line
The Microsoft Digital Defense Report 2026 makes a credible case, from Microsoft's own data, that AI is shrinking the time between a flaw and an attack, and that phishing and paste-a-command scams are doing more damage than a year ago. It does not show a wave of fully autonomous attacks; Microsoft says humans still steer most of them. The practical response is the boring one, done faster: passkeys, quick patches for internet-facing systems, and a firm no to any page that asks you to run a command. Watch for whether automated attacks like JADEPUFFER stay rare over the next few months.
FAQ
What is the Microsoft Digital Defense Report?
It's Microsoft's annual threat report, built from the company's security telemetry, incident response work and threat intelligence. The 2026 edition was published on October 1, 2026 and covers July 2025 through June 2026. It's free to download as a PDF.
Is AI-powered ransomware real?
Microsoft cites one documented case, JADEPUFFER, which Sysdig described in July 2026 as an extortion attack run by an AI agent. Microsoft says it has seen related AI-orchestrated intrusions but that volumes remain low. Most attacks it observes still have human operators directing them.
Do passkeys stop phishing?
They stop the kind of phishing that steals your login on a fake site, because a passkey only works on the real site it was made for. Microsoft recommends them alongside phishing-resistant MFA as its top identity defense. They don't stop you from being tricked into running a command or installing a remote support tool, so those habits still matter.
How fast should you install security updates now?
Microsoft's report tells organizations to fix new vulnerabilities in internet-facing and identity systems within 72 hours. For personal devices, the simplest rule is to install security updates as soon as they're offered.