Microsoft said in its 2026 Digital Defense Report that AI is speeding up attacks. Infosecurity Magazine, which dated the report October 1, 2026, said AI shrank data theft, credential discovery and lateral movement (hopping between systems) from days to minutes. It also gave Microsoft's figures on how attackers get in. Phishing rose from 7% of incidents in 2025 to 23% in 2026. Attacks on public-facing apps rose from 15% to 24%. Social engineering overall fell from 15% to 7%.
The sources do not say how Microsoft measured the days-to-minutes change. They also do not explain how the categories are defined. Phishing is a kind of social engineering, so one rising while the other falls looks odd. Do not read those figures as one total. Infosecurity said AI use likely explains part of the phishing and app-attack rises. That link is not proven. JadePuffer, a July campaign Microsoft called fully autonomous, is not described in detail.
Infosecurity quoted Microsoft calling too much standing access, meaning rights that stay switched on, the core failure. A stolen login with broad rights lets an attacker hop from system to system. If hopping takes minutes, the time those rights stay usable is the window that counts. Microsoft said a hijacked AI agent hands over the trust it has between services. So ask which admin rights are always on, and what agents can reach.