The usual way to write about AI and cybercrime is in the future tense: one day, attackers might let the machines run loose. Microsoft's 2026 Digital Defense Report, published on 1 October and drawn from more than 165 trillion security signals a day, refuses that framing. It describes autonomous AI attacks not as a coming threat but as one that has already arrived, and it names the moment it crossed over. In July, researchers at Sysdig documented JADEPUFFER, which Microsoft calls the first confirmed fully automated ransomware extortion attack: AI systems picked the targets, delivered the ransom demands, and ran the extortion with barely a human in the loop.
If JADEPUFFER is the proof in the wild, the lab results are the warning. In controlled evaluations, frontier models chained together 32 consecutive attack steps to take full control of a simulated enterprise network with no human direction at all. "AI is changing the physics of cybersecurity," the report's opening line says, and the rest of the document is an argument for why that metaphor is the right one.
The physics in question is a timing mismatch. The median gap between a vulnerability being discovered and being actively exploited has collapsed to well under 24 hours. Enterprise patching for critical internet-facing flaws still routinely takes 30 to 60 days, and not because companies are lazy. Production systems need testing before code changes ship, a constraint AI cannot wish away. Meanwhile the raw material keeps growing: nearly 40,000 vulnerabilities were catalogued in the first half of 2026 alone, putting the year on track to roughly double 2025's count. Well-resourced adversaries, Microsoft warns, can now stockpile exploits faster than any one organisation can close its own gaps.
The texture of everyday attacks is changing too. Phishing jumped from 7 percent of the intrusions Microsoft investigated a year ago to 23 percent, because AI industrialises what used to be painstaking work. The old tells of a scam, the forged document, the stilted writing, the off accent on a video call, the thin online footprint, are, in the report's blunt phrase, fixed "all four simultaneously" by AI. The same trick powers North Korea's fake-employee scheme, where deepfake video helps operatives pass job interviews and embed inside Western firms. All four major state actors, China, Russia, North Korea and Iran, are described as using AI as operational tradecraft rather than experiment, with Russia leaning on what the report calls "vibe coding" to spin up attack tools on demand.
Some of the new malware is built around AI from the ground up. One strain, s1ngularity, did not carry its own payload; it hunted infected machines for AI coding assistants already installed, then hijacked those trusted tools to go looking for secrets and keys, lifting roughly 2,000 credentials from 225 organisations. Another prototype shipped containing only prompts, generating its malicious code at runtime from a server-hosted model so that what lands on your machine is, technically, just a template.
The report is careful not to tip into despair. The same tools accelerate defence: security teams using Microsoft's Copilot reported triaging threats 60 to 70 percent faster, and a coordinated takedown cut one phishing service's activity by 95 percent. Most serious intrusions, Microsoft notes, still rely on humans for the highest-stakes choices, though it expects that limit to fade. Its single most urgent recommendation is almost mundane: treat phishing-resistant multifactor authentication and passkeys as a baseline, not an upgrade. Credential theft remains the way in. AI did not invent that weakness. It just made exploiting it cheap, fast, and increasingly hands-free.