EN
İhbar gönder

Microsoft: AI has tipped the cyber edge to attackers; a vulnerability becomes a weapon in under 24 hours, and phishing’s share of intrusions jumped from 7% to 23% in a year

According to Microsoft’s 2026 Digital Defense Report, published on 1 October, AI has given attackers the near-term advantage; the company says defenders will need to move sharply to close the gap. ☀ The median time from a vulnerability’s discovery to its weaponisation has fallen well below 24 hours; the number of recorded vulnerabilities in 2026 is on track for a record 72,000. ☀ Phishing was the entry point in 23% of intrusions Microsoft investigated, up from 7%; 44.6% of phishing pages are adversary-in-the-middle kits that defeat two-factor authentication. ☀ Government was the most targeted sector, accounting for 27% of observed activity, up from 17% a year earlier.

Microsoft Redmond kampüsü, 92 numaralı bina
ARCHIVEImage: Microsoft Redmond campus, Building 92. Photo: Coolcaesar, Wikimedia Commons, CC BY-SA 4.0, 30 May 2016. Archive image.

Microsoft published its 2026 Digital Defense Report on 1 October, drawing on 165 trillion daily security signals. Covering July 2025 to June 2026, the report concludes that AI has shifted the near-term advantage to attackers. While the equilibrium between attackers and defenders will likely be re-established eventually, Microsoft said, in the near term attackers are reaching the advantages first and defenders will need to move sharply to close the gap.

The report shows every stage of an attack accelerating. Vulnerability discovery and exploitation, which once required human experts, now in many cases comes down to simply writing a prompt, Microsoft said; the median time from a vulnerability’s discovery in the wild to its weaponisation has dropped to well below 24 hours. The number of vulnerabilities tracked for 2026 is on track for a record of about 72,000. For sophisticated actors, Microsoft says, AI reduces the attack chain from days to seconds; for less skilled actors, it makes available the scale and persistence that was once the sole domain of intelligence agencies. After a compromise, data exfiltration, credential discovery and lateral movement have shrunk from days to minutes.

Phishing is back. In intrusions investigated by Microsoft’s incident responders, phishing was the initial access vector in 23% of cases, up from 7% a year earlier. Exploits against public-facing applications rose from 15% to 24%. AI lets attackers personalise every phishing message, turning spear phishing into a mass operation and removing language barriers. Adversary-in-the-middle kits now make up 44.6% of identified phishing techniques; these pages steal live sessions rather than passwords, defeating SMS or app-based two-factor authentication. Among intrusions involving compromised accounts, 52.2% led to further credential theft.

Government was the most targeted sector, accounting for 27% of observed threat activity, up from 17% the previous year, and governments are also the most frequent targets of nation-state actors. Microsoft’s Australia and New Zealand national security officer, Mark Anderson, said that a year ago the conversation about AI and cybersecurity was about what might happen, and that this year’s data shows those theoretical risks have become reality. Microsoft’s recommendations: phishing-resistant multi-factor authentication such as hardware keys or passkeys, strict access controls and AI in defence. The warning applies directly to Turkey, where personal data leaks and phishing are widespread.

VERIFICATION STATUSLAST UPDATED 12:40
VERIFIED

The report period, 'simply writing a prompt', under 24 hours, 72,000 vulnerabilities, phishing rising from 7% to 23%, public-facing exploits from 15% to 24% and personalisation: Help Net Security, 2 October 2026. Government's 27% share (17% last year), nation-state targeting and 52.2% credential theft: Microsoft On the Issues blog, 1 October 2026. The 165 trillion signals, the three trends, Anderson's remarks and the phishing-resistant MFA recommendation: Geekzone, 2 October 2026. 'Attackers reaching advantages first' and 'days to seconds': BleepingComputer, 2 October 2026. Post-compromise timelines shrinking to minutes: SC World, 3 October 2026. The 44.6% AiTM, 33.6% URL and 12.9% attachment shares and the 1 October publication: DEV Community analysis, 3 October 2026.

UNCERTAIN

The data reflect Microsoft's own customer base and incident response cases and may not represent the whole internet. Part of the rise in phishing may reflect better visibility, as the share of cases with no identified entry point fell from 25% to 14%, according to the DEV Community analysis. The report contains no Turkey-specific data.

MISSING

The report's findings for Turkey and the region, the list of most targeted countries and ransomware statistics are not covered here.

Some stories are prepared with AI assistance; every story is reviewed and labelled by a person before publication. Real photographs are published with their source and licence; AI-generated images carry the ILLUSTRATIVE label.

Leave a comment

No account needed. Your email address is not published. Comments are reviewed before they appear.