The Report Named Models
Microsoft's 2026 Digital Defense Report, drawn from the 165 trillion security signals the company analyses daily, does something vendor threat reports normally avoid. It names specific frontier models.
Anthropic's Mythos and OpenAI's GPT-5.5 demonstrated the ability to "orchestrate complex attacks on their own", including a 32-step attack chain that achieved complete domain control.
Not "AI-assisted attackers". Not "an advanced model". Two products, by name, in a report from the company that sells the security stack defending against them.
The Number That Is a Countdown
The most useful figure in the document is not about the frontier at all: open-weight models lag closed models in attack orchestration by seven months.
Every other finding here is a snapshot. That one is a clock. It says whatever a frontier lab can gate behind a safety review today arrives in a downloadable, unmonitorable, ungateable model in roughly two quarters - and the only lever anyone has on the gap is whether open-weight releases speed up.
If you are planning security posture, that is your planning horizon. Capability demonstrated at the frontier now is capability in the wild by roughly May.
Weaponisation Is Now Faster Than Patching
Median time from vulnerability discovery to weaponisation: well below 24 hours. Microsoft expects roughly 72,000 CVEs for 2026, a record pace.
Under a day, against an industry where monthly patch cycles are still normal, is the whole problem in one sentence. The window between a vulnerability becoming known and becoming exploited is now shorter than most organisations' approval process for applying a patch.
How Attackers Get In
| Entry vector | 2026 | Year before |
| Public-facing application exploit | 24% | 15% |
| Phishing | 23% | 7% |
Phishing more than tripled as an initial compromise vector in a single year. That is the clearest signal in the report of what generative models have changed - not novel attack techniques, but the cost of writing a convincing message at scale collapsing to nearly nothing.
Identity is the rest of the story. 52.2% of intrusions begin with valid accounts and then harvest further credentials, and 18.4% involve active password spray campaigns. Most of what the report describes is not breaking in. It is logging in.
Automation Has Already Happened
Three incidents in the report mark the shift from theory to record:
- July 2026 - JADEPUFFER. The first documented fully automated ransomware extortion attack.
- August 2025 - S1ngularity. Approximately 2,000 secrets and 20,000 files taken from 225 victims.
- December 2025 - a malicious browser extension. Over 600,000 installs, affecting nearly 10,000 organisations.
The browser extension is the one worth sitting with, given how many AI tools now ship as exactly that.
What To Do About It
Nothing in the report points at exotic defences. The findings point at identity and speed.
- Phishing-resistant MFA everywhere. 52.2% of intrusions start with valid credentials, and the phishing that harvests them tripled.
- Patch windows measured in hours, not months. Weaponisation beat you to it by default at sub-24-hour median.
- Audit browser extensions as software. 600,000 installs reached 10,000 organisations through a channel most inventories do not cover.
- Assume open-weight parity by mid-2027. Seven months is the published lag; plan the defence for the capability, not for the gate in front of it.
Microsoft's own framing is that threat actors are ahead in the early AI race. The data in the report supports it, and notably none of the countermeasures above require buying anything new.
Two earlier pieces give this context: OpenAI's Astra crossing a critical cybersecurity threshold, and the agent that reached a DNS resolver during evaluation while the automated stop failed.
FAQ
Which AI models did Microsoft name?
Anthropic's Mythos and OpenAI's GPT-5.5, both cited as able to orchestrate complex attacks unaided, including a 32-step chain achieving complete domain control.
How fast are vulnerabilities being weaponised?
Median time from discovery to weaponisation is well below 24 hours, against roughly 72,000 CVEs expected for 2026.
How far behind are open-weight models?
Seven months at attack orchestration, per Microsoft's measurement - which makes it a timeline rather than a safety margin.
What was JADEPUFFER?
The designation Microsoft gave to the first documented automated ransomware extortion attack, in July 2026.