Microsoft published its 2026 Digital Defense Report on 1 October 2026, covering July 2025 to June 2026. Its thesis is that AI is changing the economics of attack and defence, and that attackers are getting the benefit first. In the report's own words, this is a period where attackers are reaching advantages first and defenders will need to move sharply to close the gap.
That is the headline everyone ran. The figures underneath it are more useful, and most of them are not about AI at all.
The arithmetic that decides everything
Three numbers sit together in the report and explain more than any single finding.
Nearly 40,000 CVEs were published in the first half of 2026, a pace that would roughly double previous annual totals. The median time from a vulnerability being discovered to being weaponised is, Microsoft says, well below 24 hours. The time enterprises take to remediate critical externally facing vulnerabilities is 30 to 60 days.
Put them in order and the defensive problem is arithmetic rather than technology. The attacker's side of that comparison is measured in hours. The defender's is measured in weeks. Everything else — tooling, detection, staffing — is an attempt to operate inside a gap that is currently two orders of magnitude wide.
AI does not create that gap. It compresses the left-hand number, which was already the smaller one.
The flaw that will not die
The finding that should embarrass the industry is quieter. Among detections tied to the five leading CVEs, 58 percent were associated with CVE-2020-1472 — the Netlogon elevation flaw disclosed in 2020, patched for six years.
A six-year-old vulnerability producing the majority of detections in that group says something uncomfortable about where effort goes. The reporting cycle, the budget cycle and the attention cycle all run on what was disclosed this week. The detections run on what was never finished.
If an organisation has to choose between reading a frontier-AI threat report and confirming that every domain controller it owns has the 2020 patch, Microsoft's own numbers say which one pays.
Where AI genuinely shows up
The report does describe real AI involvement, and it is careful about the line between capability and practice.
In controlled testing, frontier systems executed 32-stage attack chains. Microsoft points to the first documented case of automated ransomware extortion — the operation Sysdig named JADEPUFFER and published on 1 July 2026 — as an early real-world instance. And Microsoft Threat Intelligence reports AI applied across vulnerability discovery, reconnaissance, phishing, malware development and post-compromise work.
But the qualifier is the report's own: most observed campaigns still retain human direction, even as frontier systems demonstrate end-to-end autonomy in labs and early real-world cases. That is a narrower claim than the coverage of it. The autonomous end-to-end attack is demonstrated and documented; it is not yet what most intrusions are.
It sits alongside what the Dutch disclosure body said about its own breach last week, where the evidence for an agent was behavioural rather than forensic. Both are early data points, and both deserve to be read as early data points.
The technique that scaled without any of this
The largest single number in the report belongs to a technique that needs no model at all.
Between February and early May 2026, Microsoft Defender observed attacker-supplied commands executed through ClickFix on more than 1.1 million unique devices — roughly an eightfold increase. ClickFix is the page that tells a visitor verification failed and asks them to paste a line into a terminal, which we wrote about this week in its Custom GPT form.
Alongside it, Microsoft puts user execution at 30 percent of observed initial access and valid accounts at 20 percent. Half of all initial access, in other words, is either a person running something or an attacker signing in as someone who was allowed to.
No exploit chain. No model. A person following instructions, and a password that worked.
What to do
- Finish the old work first. Confirm CVE-2020-1472 is patched everywhere, including the domain controller nobody has touched since it was built. Microsoft's detection data says that one line item outranks most of this year's roadmap.
- Treat terminal paste as a detectable event. Shell launches with clipboard-shaped arguments and script execution from temporary folders are both observable, and 1.1 million devices is the argument for bothering.
- Close the window you can actually control. If weaponisation is under a day, the lever is not patching faster than that — it is reducing what is externally reachable, so fewer of those hours matter to you.
- Read the AI findings at their stated altitude. Demonstrated in labs and in early cases is not the same as the median intrusion, and the report says so.
What is not established
- How Microsoft measures weaponisation, and what the distribution behind the median looks like.
- Whether the 40,000 CVEs in six months reflects more flaws, more reporting, or more automated discovery.
- How much of the observed AI-assisted activity would have succeeded without AI, which the report does not attempt to separate.
- What share of the 1.1 million ClickFix devices resulted in a completed compromise, as opposed to a command that ran.