Microsoft Threat Intelligence reposted this
AI is changing the physics of cybersecurity. But faster attacks don’t make the fundamentals less important. They make the cost of getting them wrong higher. Three findings from the 2026 Microsoft Digital Defense Report bring that into focus: • Exposed container workloads faced their first exploit attempt a median of just 5.3 hours after starting. • In Microsoft Defender Experts customer notifications, user execution accounted for 30% of observed initial access activity, and valid accounts another 20%. • Among valid-account intrusions, 52.2% involved follow-on credential theft. One compromised identity becomes a path to more. These are different datasets, but together they illustrate the challenge: threat actors can move quickly through access and trust that already exist inside an organization. At Black Hat this year, I discussed how threat actors follow trust. A software dependency. A developer workflow. A legitimate credential. Increasingly, an AI agent’s access to data and tools. AI can accelerate discovery and exploitation of those weaknesses. It can also help defenders find exposure earlier, connect signals faster, and shorten the time from investigation to response. But more information alone won’t close that gap. Threat intelligence has to connect with the context of the organization and change what defenders do next. In my latest blog, I explore what this year’s report means for security leaders: strengthening the foundations, securing AI systems and agents, and using AI to turn intelligence into faster action. As the distance between discovery and attack shrinks, we need to close the distance between intelligence and action. Read the blog: https://lnkd.in/gsBpnc5V