Defenders are left with increasingly less time between the disclosure of a vulnerability and the initial attack. Microsoft tallied nearly 40,000 published CVEs in the first half of 2026 alone, warning that artificial intelligence compresses the preparation time for certain attacks from days to mere hours or even minutes.
Within the comprehensive Microsoft Digital Defense Report, the corporation delineates how AI facilitates the discovery of vulnerabilities, the fabrication of phishing lures, the analysis of exfiltrated data, and the orchestration of exploits for identified flaws. In one remarkable experiment, an autonomous system independently navigated a labyrinthine 32-stage attack chain.
The Shrinking Window for Defenders
The temporal window between the detection of a vulnerability and the emergence of a weaponized exploit is contracting at an alarming velocity. The median duration has plummeted below 24 hours. Conversely, enterprises frequently require between 30 and 60 days to remediate critical vulnerabilities within their external-facing systems. Microsoft has previously cautioned that conventional update cycles are becoming increasingly inadequate against the blistering pace of modern cyberattacks.
The sheer volume of discovered flaws is concurrently surging. However, the accumulation of nearly 40,000 CVEs within a six-month span does not intrinsically imply that software has grown inherently less secure. Instead, artificial intelligence empowers researchers to rapidly audit colossal volumes of code, unearthing latent errors that historically might have remained undetected for extended periods.
AI as a Double-Edged Sword
Malicious actors wield this identical technology to dissect security patches, juxtapose software iterations, and actively hunt for viable exploitation pathways. Nevertheless, fully autonomous, highly complex cyberattacks have not yet solidified into the prevailing norm. In numerous instances, human operators must still actively oversee and guide the system’s actions.
The report highlights another highly revealing metric: internet-facing cloud infrastructures encounter their first attack, on average, a mere 5.3 hours after deployment. Against this unforgiving backdrop, the traditional paradigm – wherein updates are methodically studied, exhaustively tested, and deployed according to rigid schedules – leaves an unacceptably expansive window of opportunity for adversaries.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.