Microsoft published its 2026 Microsoft Digital Defense Report on October 2, 2026, saying threat actors are incorporating AI into reconnaissance, social engineering, malware and exploit development, and post-compromise activity. The company said the report reflects "a security environment that continues to grow more interconnected."
What Microsoft says about AI in the threat landscape
According to the report, much of attackers' use of AI remains focused on specific parts of existing attack workflows, even as more advanced applications continue to develop.
Microsoft said AI can give threat actors greater speed, scale and the ability to tailor activity more efficiently, pointing to more targeted social engineering campaigns and to automation that compresses parts of the attack process. The underlying methods often remain familiar, the company said, with people, identities, exposed systems and trusted access continuing to feature prominently in the activity Microsoft observes.
Securing AI agents as part of the enterprise
The report treats agents as an example of growing interconnection. Microsoft said agents can interact with enterprise data, applications, APIs and tools, with different levels of access and autonomy depending on how they are designed and deployed.
A model may be one component, Microsoft said, but its security also depends on the data it can reach, the tools it can use, the identities and permissions involved, and the surrounding infrastructure and services.
The report examines agent identity, appropriate access, authentication between agents, attribution and the ability to revoke access, as well as security considerations specific to AI including prompt injection, memory, models and data, agent behavior, and the integrity of software and services around AI systems.
Vulnerability discovery and defender workflows
Microsoft said advances in applying AI to code analysis make it possible to examine software and identify weaknesses more effectively, creating opportunities to find vulnerabilities earlier. The company added that the same advances can give threat actors more capable tools for vulnerability discovery and exploit development.
On the defensive side, the report argues that signals from endpoints, identities, cloud environments, applications, email, networks and threat intelligence become more useful when considered together, because activity spanning several systems may leave a pattern that no individual source shows on its own. Microsoft also pointed to trusted intelligence sharing across organizations and public-private partnerships.
In its discussion of red teaming, Microsoft said connecting known information and running established techniques can increasingly be automated, while finding an undocumented attack path or recognizing how apparently unrelated weaknesses fit together continues to benefit from experienced operators staying close to the work.
Sector impact
In a related Microsoft post dated October 1, the company said that according to this year's report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025.
The blog post on the report was written by Terrell Cox, CVP and Deputy CISO in Microsoft's Customer Security Management Office.
What to do
- Microsoft says security teams have a strong foundation to build from: identity and authorization, data protection, least privilege, monitoring, testing and secure software development all remain relevant as AI is added to enterprise workflows.
- Treat AI as part of a broader system, Microsoft says, assessing the data a model can reach, the tools it can use, the identities and permissions involved, and the surrounding infrastructure and services.
- For agents, the report points to agent identity, appropriate access, authentication between agents, attribution and the ability to revoke access as areas to address.
- Correlate signals from endpoints, identities, cloud, applications, email, networks and threat intelligence, since Microsoft says cross-system activity may leave patterns no single source shows.
- Consider automating established, repeatable defensive techniques while keeping experienced operators on work such as finding undocumented attack paths, Microsoft says.
- Microsoft encourages reading the full 2026 Digital Defense Report for its findings, data and recommendations.
Key facts and where they come from
- Microsoft released its 2026 Digital Defense Report, describing a more interconnected security environment.
Today, we released the 2026 Report, which reflects a security environment that continues to grow more interconnected.
- Attackers are using AI across several stages of intrusions.
Threat actors are incorporating AI into reconnaissance, social engineering, malware and exploit development, and post-compromise activity.
- Microsoft says attacker use of AI is still largely confined to parts of existing workflows.
much of their use remains focused on specific parts of existing attack workflows, even as more advanced applications of AI continue to develop
- The report covers AI-specific security topics such as prompt injection and agent behavior.
including prompt injection, memory, models and data, agent behavior, and the integrity of software and services around AI systems
- AI-assisted code analysis helps both defenders and attackers find weaknesses.
Those same advances can give threat actors more capable tools for vulnerability discovery and exploit development.
- Government was the most affected sector in 2026, per Microsoft's related post.
government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025
