A cybersecurity analyst monitors a digital network, tracking threats and securing cloud systems from a control room.
Microsoft's 2026 Digital Defense Report is out, and its main message is easy to state and harder to act on. Attackers are getting faster with AI, but they still mostly get in through people, identities and trusted access. AI agents are now a new attack surface. The defenders who do best will be the ones who connect signals that most organizations still keep in separate tools.

The report was released on October 1, 2026. Terrell Cox, Microsoft's CVP and Deputy CISO for its Customer Security Management Office, wrote the accompanying blog post. The data covers July 2025 through June 2026, and the report is organized around four themes: AI, the threat landscape, cybercrime and resilience. Below are the main findings, how they compare with last year, and what Windows and Microsoft 365 administrators should do with them.

Microsoft's telemetry, and how it compares with last year​

Microsoft's landing page for the report lists the company's own operating figures:

  • More than 165 trillion security signals processed daily
  • 4.7 million net new malware file blocks every day
  • 31 million identity risk detections analyzed on an average day
  • An average of 5.2 billion emails screened daily
  • 35,000 full-time-equivalent security engineers and 15,000+ ecosystem partners

Compare those with last year. A Microsoft Security blog post from May 2026, citing the 2025 report, said Microsoft now processes more than 100 trillion security signals, blocks approximately 4.5 million new malware attempts, analyzes 38 million identity risk detections, and screens 5 billion emails for malicious content each day.

So signal volume went up by roughly 65% year over year. Malware blocks and email screening rose modestly. Daily identity risk detections fell from 38 million to 31 million.

The drop in identity detections is notable because this year's report calls identity the main battleground. Microsoft doesn't explain the change on the landing page. Possible reasons include changes in detection logic, tuning that cut noise, or fewer risky sign-ins. These are Microsoft's own unaudited figures, and the wording differs between years ("new malware attempts" versus "net new malware file blocks"), so treat the comparison as directional, not exact.

Section summary: Microsoft's visibility keeps growing, but the year-over-year numbers aren't fully comparable, and one of them went down.

AI makes attacks faster without changing the basic methods​

Cox's post avoids hype on AI. Microsoft sees threat actors using AI for reconnaissance, social engineering, malware and exploit development, and post-compromise activity. However, most of that use still targets specific steps of existing attack chains rather than replacing the whole operation.

The report's own summary is stronger. It says AI is "compressing attack timelines" and lowering the cost of sophisticated capabilities, while also speeding up defensive discovery, analysis, prioritization and response.

The underlying methods remain the same. The report lists user execution, ClickFix-style social engineering, phishing and impersonation as persistent ways in. AI makes these lures better targeted, but they work for the same reasons as before.

The cybercrime figures support this:

Metric (Microsoft-reported)Figure
Intrusions involving data theft63%
Average time before exposed cloud workloads were attacked5.3 hours
Voice-phishing attacks that held the victim long enough to start social engineering93%
Business email impersonation attacks detected (12 months)46 million+
Email phishing attachments leading to credential theft attempts89–95%
Valid-account intrusions with follow-on credential theft52.2%
QR-code phishing attacks detected by Defender for Office 365145 million+
Year-over-year increase in enterprise ransom detonations15.8%
Critical-infrastructure attack techniques using cloud identity abuse78%

Two figures matter most for operations:

  • 5.3 hours. That's how long an exposed cloud workload lasts, on average, before it's attacked. A misconfigured VM or storage endpoint created before lunch can be under attack before the end of the workday. If changes go through a weekly review, exposures won't be caught in time.
  • 52.2%. In more than half of valid-account intrusions, the attacker went on to steal more credentials. One compromised account tends to lead to more.

Microsoft also describes a disruption action. In March 2026, it worked with law enforcement and industry partners against the Tycoon2FA phishing service. Microsoft says Tycoon2FA activity fell 95% from its November 2025 peak by June.

Section summary: AI speeds up attacks, but identity theft, phishing and exposed assets are still how attackers get in.

Agents are now an attack surface​

This part of the report is the most new. Cox writes that a model is only one component of an AI system. Its security also depends on the data it can reach, the tools it can call, its identities and permissions, and the infrastructure around it.

The report cites survey data: 88% of enterprises are experimenting with AI agents, 82% of leaders plan broader rollouts within 12 to 18 months, and industry projections point to about 1.3 billion agents in production by 2028. The landing page doesn't give the methodology behind these numbers, so treat them as indicators of direction, not precise measurements.

It also includes an example. In December 2025, Microsoft found a malicious browser extension with more than 600,000 installs that was harvesting ChatGPT and DeepSeek conversation history. Nearly 10,000 organizations were affected before it was stopped. Microsoft notes that LLM chat histories now regularly contain source code, architecture details, customer data and leaked credentials. Few organizations treated their browser extension allowlist as AI security until now, but it is.

The report groups agent risks into five classes and pairs each with controls:

  • Prompt and intent manipulation. Instructions hidden in prompts, content, files or memory redirect the agent. Controls: prompt-injection detection, payload inspection, intent validation, output review.
  • Sensitive data exposure. The agent is pushed to read or return content outside its sanctioned scope. Controls: sensitivity-aware retrieval, response inspection, data loss prevention (DLP) on inputs and outputs, memory scoping.
  • Identity and privilege compromise. An attacker impersonates a sub-agent, reuses stolen credentials, or chains privileges across agents. Controls: verifiable agent identity, mutual authentication, scoped credentials, least privilege.
  • Excessive agency. The agent is coaxed into chaining tools or actions beyond what it's allowed to do. Controls: tool allow-listing, runtime gating, action policy, anomaly detection.
  • Operational integrity. Someone tampers with configuration, system prompts, memory, training data, the supply chain or logs. Controls: immutable logs, signed configuration, change governance, supply chain attestation.

Cox also lists questions about agent identity that most organizations can't yet answer well: how agents authenticate to each other, how to attribute an agent's actions, and how to revoke an agent's access quickly. That last question will matter in incident response. If you can't quickly disable a compromised agent, you can't contain the incident.

The report's heading on this topic says to "govern agent identity before agents outnumber people." The landing page says identity now covers "both human and non-human identities, including applications and agents." Microsoft's Storm-3168 write-up, published the week before the report, described agentic cloud attacks that used compromised service principals, a real example of non-human identities being abused.

Section summary: Treat each agent like a privileged service account that can be talked into misbehaving. Inventory it, scope it, monitor it and make sure you can shut it off.

AI vulnerability discovery cuts both ways​

Cox notes that AI-assisted code analysis is getting better at finding software weaknesses. That helps defenders fix bugs before they ship, and it helps attackers find bugs to exploit.

The post doesn't give specifics: no model, no measured improvement, no example CVE. Microsoft calls it "an important area to watch," and the report doesn't yet back it with numbers. The practical effect is that the time between a vulnerability's disclosure and its exploitation may get shorter, so patch timelines that assume weeks of grace are riskier.

Correlating signals​

The report says the degree to which a defender correlates threat intelligence across endpoint, identity, cloud, application, email and network telemetry is "one of the highest-leverage strategic variables under the defender's control." An attack spread across several systems can leave a pattern that no single log shows on its own.

Two caveats:

  • Vendor interest. Microsoft sells a platform built on correlating these signals, and the report says organizations using Security Copilot summarize threats 60–70% faster. That figure is self-reported customer data, not an independent benchmark. The principle is still sound: correlation across sources works whether the tools come from one vendor or several.
  • Human judgment still matters. Cox's discussion of red teaming makes the point: connecting known information and running established techniques can be automated, but finding an undocumented attack path, or seeing how unrelated weaknesses combine, still needs experienced people close to the work.

The report also recommends moving from tool-centric vulnerability management to threat exposure management. That means tracking exposure reduced, detection coverage gained and time-to-mitigate shortened, rather than counting patches deployed.

Government is the most-targeted sector​

In a companion post, Mike Yeh, Microsoft's Vice President and Deputy General Counsel, writes that government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. He adds that governments are also the most frequently targeted sectors for nation-state activity. He also notes that dwell time, the period between when an attacker gains access and when defenders detect and stop them, also increased this year across multiple sectors.

The report ranks IT (17%) and research and academia (14%) next among sectors. Among state and local government and education targets, research and academia accounted for 38% of observed attacks between November 2025 and April 2026. Customers in the United States accounted for 25.5% of observed threat activity from January 2025 through June 2026.

Rising dwell time is the uncomfortable number here. Attacks are getting faster, but defenders are taking longer to notice them in many sectors.

What Windows and Microsoft 365 admins should do​

These steps follow from Microsoft's recommendations. They are general security guidance, not product configuration steps:

  • Move to phishing-resistant authentication. The report names phishing-resistant MFA and passkeys, along with tiered administration and enforced privileged access, as the best defenses. With 89–95% of phishing attachments leading to credential theft attempts, push-approval MFA isn't enough.
  • Inventory non-human identities. List service principals, app registrations and agents, along with their permissions and credential lifetimes. Remove standing privileges wherever you can.
  • Plan how to revoke agent access. For each agent in production, know how to disable it, rotate its credentials and review what it did.
  • Reduce data oversharing before rolling out more AI. Microsoft's guidance is to apply sensitivity-aware access, least privilege and governance over how agents find and share data.
  • Monitor for new exposures continuously. A 5.3-hour window means newly exposed cloud assets need automatic detection.
  • Audit browser extensions. The extension that harvested chat histories shows that unmanaged extensions can leak AI conversation data.
  • Correlate your logs. Identity, endpoint, email and cloud logs that never meet each other leave the gaps where long dwell times come from.
  • Train staff against voice phishing and QR-code lures. The 93% voice-phishing figure suggests attackers rely on callback scams and helpdesk impersonation.

The bottom line​

The 2026 report doesn't predict a sudden AI takeover of cybercrime. Microsoft's view is that AI makes familiar attacks faster and cheaper, adds agents as a new and often poorly governed attack surface, and rewards defenders who correlate signals and keep experienced people involved.

Some of the headline numbers are Microsoft's own and come with limited methodology on the landing page, and some of the recommended controls map to products Microsoft sells. Even so, the core advice holds up without them: secure identities, govern agents, limit data exposure, and detect exposed assets within hours.


Update: Additional details (October 1, 2026)​

BleepingComputer reports that Microsoft’s report puts a sharper number on the AI-assisted vulnerability problem: the median interval between a vulnerability being discovered in the wild and being weaponized has fallen “well below 24 hours.” Microsoft also warns that AI-driven discovery could create a multi-year rise in known but unpatched flaws, because finding weaknesses can accelerate much faster than organizations can test and deploy fixes.

The report further says AI is shortening post-compromise work such as secret discovery, lateral movement and data theft from days to minutes. Microsoft says Chinese, Russian and North Korean state-backed operators are already using AI in parts of real-world operations, including vulnerability research, AI-generated tooling, malware development, persona creation and attack infrastructure management. It still says most campaigns retain human direction rather than running fully autonomously.

 

References

  1. Microsoft says threat actors are ahead in the early AI race BleepingComputer 2026-10-01T15:32:47-04:00
  2. Insights from the 2026 Microsoft Digital Defense Report Microsoft 2026-10-01T14:00:00+00:00
  3. Defending consumer web properties against modern DDoS attacks microsoft.com