Microsoft Says Attackers Are Beating Defenders in the AI Race


microsfot ai security
Image credit: Microsoft

Microsoft says cyberattackers are currently benefiting from AI faster than defenders, giving threat actors a short-term advantage as artificial intelligence rapidly changes how cyberattacks develop.

According to Microsoft, AI is accelerating vulnerability discovery, malware development, data theft, secret discovery, and lateral movement inside compromised networks. The technology also lowers the cost and technical expertise required to launch sophisticated attacks.

Microsoft expects defenders to eventually catch up, but organizations will need to move quickly to close the current gap.

AI is speeding up vulnerability exploitation

One of the biggest concerns involves vulnerability discovery. Microsoft says AI-assisted research can uncover security flaws faster than many organizations can patch them.

The median time between a vulnerability appearing in the wild and attackers weaponizing it has fallen well below 24 hours. That leaves organizations with increasingly little time to test and deploy updates before attackers begin exploiting newly discovered flaws.

Microsoft warns this could lead to a multi-year increase in known but unpatched vulnerabilities, particularly at organizations that cannot safely roll out software fixes immediately.

Well-funded attackers could also use AI to discover and stockpile large numbers of zero-day vulnerabilities for future operations.

Sophisticated attacks can shrink from days to seconds

AI can dramatically accelerate individual stages of an attack chain.

Microsoft says tasks that previously took attackers days can sometimes take seconds with AI assistance. Threat actors can use AI to create customized malware, automate reconnaissance, search for exposed credentials and secrets, and move through compromised environments faster.

Attackers can also automate larger portions of an operation with less human involvement.

This shift makes advanced techniques more accessible to less-skilled cybercriminals, who can use AI to perform tasks that previously demanded significantly more technical expertise.

Nation-state hackers are already using AI

Microsoft says Chinese, Russian, and North Korean state-linked threat actors have already incorporated AI into real-world operations.

Chinese threat groups have used AI for vulnerability research, while Russian actors have experimented with AI-generated tools and so-called “vibe coding.”

North Korean groups have used AI across a broader range of activities, including malware development, fake personas, social engineering campaigns, and attack infrastructure.

Despite these developments, Microsoft says most cyberattacks still require human direction, particularly when choosing targets and making complex operational decisions.

Fully autonomous attack chains have appeared in research and some early real-world incidents, but they have not yet become the norm.

In other AI security news, OpenAI agents recently accessed Australian government systems, after which OpenAI apologized.

Separately, the JadePuffer attack showed how destructive AI-assisted operations can become after attackers used AI agents to wipe Azure resources in minutes.

Via BleepingComputer

More about the topics: AI, Cybersecurity, microsoft

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages