Microsoft’s 2026 Digital Defense Report says cyber risk is increasingly interconnected across identities, endpoints, cloud environments, applications, infrastructure, and software supply chains. Government agencies and services were the most targeted sector in Microsoft-observed activity, accounting for 27% between July 2025 and June 2026, up from 17% the prior year. Phishing represented 23% of observed intrusions, while compromised identities, exposed applications, social engineering, and legitimate administrative tools remained leading access paths; 52.2% of intrusions involving valid accounts resulted in additional credential theft.
The report assesses that attackers currently gain greater near-term advantage from AI, using it to accelerate reconnaissance, vulnerability discovery, phishing, malware and exploit development, and post-compromise activity. Microsoft warns that AI-assisted flaw discovery may outpace patch validation and deployment, reducing exploitation windows to less than 24 hours, and cites activity by China-, Russia-, and North Korea-linked operators, though attacks generally still require human direction. It recommends cross-domain telemetry correlation, rapid incident coordination and continuity planning, public-private intelligence sharing, and AI-agent controls covering identity, authorization, data and model security, prompt injection, agent memory, behavior, and revocation of access.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft released its 2026 Digital Defense Report, describing an interconnected threat environment and reporting that government agencies and services were the most impacted sector in its observed activity. The report assessed that attackers are already using AI across established attack workflows and currently gain a near-term advantage as AI-assisted vulnerability discovery and exploitation accelerate.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
mkd-cirt.mk
Open sourceblogs.microsoft.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.