Share on social
Oct 8, 2026
Lorem ipsum

This story appeared in our weekly cybersecurity newsletter Beacon. Sign up to get weekly updates on the latest news, findings and insights, straight to your inbox every Thursday at 10AM.
Top Story This Week:
Microsoft Warns AI Has Cut Attack Timelines from Days to Minutes
Microsoft's Digital Defense Report 2026 warns that artificial intelligence has radically accelerated cyberattacks, outpacing traditional defenses. Post-compromise activity such as credential discovery, lateral movement and data exfiltration, which once took days, can now take minutes.
AI is now used across the whole attack lifecycle. Finding vulnerabilities in source code, binaries and AI serving systems, tailoring phishing at scale, and generating custom malware. Microsoft says attackers are starting to move towards fully autonomous campaigns, pointing to the JadePuffer activity seen in July.
The report stresses that very little involves new attack methods, but the problem is the sheer increase in scale and speed, which Microsoft expects to grow as AI agents are used more widely. For the most sophisticated actors, campaigns are highly customized and need very little operator involvement.
Exploitation of public-facing applications rose from 15% to 24% of incidents between 2025 and 2026, likely driven by AI-assisted vulnerability discovery. Phishing as an initial access method climbed from 7% to 23%, partly thanks to generative AI producing convincing, personalised messages, even though social engineering overall fell from 15% to 7% of incidents.
Why it Matters
As a security professional, it's easy to be skeptical of the hype and uncertainty around AI. But if you look at the numbers from real incidents, the tried and tested methods attackers already use are now running much faster than many organizations' current cybersecurity responses can match.
Defenders have always relied on time to detect, investigate and respond before an attacker acted. AI is now eroding that buffer from both ends, with attackers finding entry points quicker, and escalating rapidly once inside. The same picture is reflected in the exploitation timelines of novel vulnerabilities. The Zero Day Clock puts mean time to exploit at around eight hours in 2026, compared with 56 days in 2024.
Faster detection and response still matter, but a program that only starts when an incident is detected is inherently reactive. That is the case for preemptive cybersecurity, the approach of identifying and reducing exploitable exposure before attackers can use it.
What this Means for Practitioners
Ensure you have a continuous and comprehensive view of your public-facing apps, as they are now involved in almost a quarter of incidents. Understand what attackers can reach, not just what exists on your attack surface.
Confirm which exposures can really be exploited in your environment, then prioritize remediation based on observed attacker activity rather than severity scores alone.
Close the identity gaps. Microsoft calls out phishing-resistant MFA, tiered administration and tighter privileged access to limit standing access.
Assume minutes, not days. Ensure high-risk external exposures and attack paths are identified continuously, rather than relying on periodic assessments.
What this Means for Security Leaders
Put greater weight on prevention. Detection and response remain essential, but when attackers can compress parts of the attack lifecycle from days to minutes, there is less time to react once they gain access. Stress-test whether your escalation paths and response processes can keep pace.
Measure the exposure window, not the size of the backlog. Look at how long validated exploitable exposures remain open, as they can now be weaponized within hours.
Plan for prevention to become a larger part of the security mix. Gartner expects preemptive solutions to account for 50% of IT security spending by 2030, up from under 5% in 2024. Consider how prevention fits alongside existing detection and response investments.
Discover More
How Modern ASM Uncovers Hidden Risks in Real Time
Real-time asset discovery is no longer a luxury. It is the baseline requirement for risk reduction. Organizations must identify new systems the moment they become accessible, not days or weeks later. In this blog, learn how the traditional perimeter has expanded, why legacy tools miss critical exposures, and how modern Attack Surface Management can help organizations to uncover hidden risks in real time. Read more.
The Preemptive Cybersecurity Handbook
This week we've launched "The Preemptive Cybersecurity Handbook". It's a practical guide to a different way of thinking about security: understanding where you're exposed, seeing your organization through an attacker's eyes, and taking action before threats become incidents. Download and read the book for free at the link below, and find out how to put preemptive cybersecurity into action for your organization. Read more.
Weekly News Digest
Operation KillSwitch, which was led by German authorities, resulted in 110 terabytes of data being secured. KillSec began operating in 2024 and is linked to approximately 1000 attacks worldwide. The group posted its latest victim to its leak site on September 18th, just 12 days before law enforcement action took place. Three arrests were made and five servers used to manage the group’s activities and store stolen data were seized, as well as multiple domains operated by KillSec.
ShinyHunters Hacker in FBI Data Theft Detained in Jordan, Cooperating with Bureau, Sources Say
Saif al-Din Khader, who goes by the alias “Rey” and is believed to be a member of ShinyHunters, was taken into custody in Jordan. Reports indicate he is actively assisting the FBI and international authorities by providing intelligence to help pinpoint and apprehend his co-conspirators. His detention coincides with disruption to the group’s dark web extortion platform, and comes shortly after the arrest of another suspected ShinyHunters operator in the Netherlands.
Warlock Ransomware Attackers Hit Water and Telecom Operators
Recent attacks involving the Warlock ransomware group show a growing threat to critical infrastructure, with attackers targeting organisations including a water utility and telecommunications provider. The China-linked group is continuing to exploit vulnerabilities in Microsoft SharePoint to gain access before disabling security software and deploying ransomware across multiple systems. The activity highlights how unpatched vulnerabilities and the misuse of legitimate tools can allow attackers to move quickly through networks and disrupt essential services.






