Microsoft warns that threat actors are currently using artificial intelligence to move faster than defenders, giving attackers an early advantage. In its 2026 Digital Defense Report, covering July 2025 to June 2026, Microsoft says AI is being used to accelerate steps such as vulnerability discovery, malware development, and activity after initial access.
The report frames the period ahead as a “near-term” gap, where attackers collect AI benefits first while defenders need to respond quickly to close it. Microsoft describes this shift as changing how cybersecurity works, implying that existing processes for finding and fixing bugs may not keep pace with AI-enabled exploitation timelines.
Across outlets, the emphasis is on speed and the resulting pressure on security teams, rather than on a specific new malware campaign. Both sources present Microsoft’s assessment as a forward-looking warning that attackers may benefit from AI faster during the early stages of adoption, increasing the urgency for defensive adaptation.