Microsoft Warns AI Is Letting Hackers Strike in Minutes, Not Days
Microsoft's Digital Defense Report 2026 warns that artificial intelligence is dramatically speeding up cyber attacks, with some stages of an intrusion now taking minutes instead of days. The report found that attackers are using AI to find vulnerabilities, scale up convincing phishing campaigns, and even generate custom malware. Once inside a network, AI is helping criminals exfiltrate data, discover credentials and move laterally far faster than before, with sophisticated groups needing little human input to run these campaigns.
Microsoft notes that while these attack techniques are not new, the sheer speed and scale enabled by AI creates an urgent problem for defenders, who are currently struggling to keep pace. The report also pointed to the rise of fully autonomous AI driven attacks, referencing the JadePuffer campaign identified in July, as a sign of what is coming next. Complicating matters further, businesses now rely on sprawling, interconnected networks of partners, vendors, cloud services and AI agents, meaning a single compromised AI agent can give attackers access to a much wider web of trusted systems.
Microsoft's recommendation is for organisations to fight AI-speed attacks with AI-powered defences, including tools that connect threat intelligence and security signals in real time to detect and respond faster.