Back to blog

Blog Post

Beacon: Microsoft Warns AI has Cut Attack Timelines from Days to Minutes

Share on social

Oct 8, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Beacon: Microsoft Warns AI has Cut Attack Timelines from Days to Minutes

This story appeared in our weekly cybersecurity newsletter Beacon. Sign up to get weekly updates on the latest news, findings and insights, straight to your inbox every Thursday at 10AM.

Top Story This Week:

Microsoft Warns AI Has Cut Attack Timelines from Days to Minutes

Microsoft's Digital Defense Report 2026 warns that artificial intelligence has radically accelerated cyberattacks, outpacing traditional defenses. Post-compromise activity such as credential discovery, lateral movement and data exfiltration, which once took days, can now take minutes.

AI is now used across the whole attack lifecycle. Finding vulnerabilities in source code, binaries and AI serving systems, tailoring phishing at scale, and generating custom malware. Microsoft says attackers are starting to move towards fully autonomous campaigns, pointing to the JadePuffer activity seen in July.

The report stresses that very little involves new attack methods, but the problem is the sheer increase in scale and speed, which Microsoft expects to grow as AI agents are used more widely. For the most sophisticated actors, campaigns are highly customized and need very little operator involvement.

Exploitation of public-facing applications rose from 15% to 24% of incidents between 2025 and 2026, likely driven by AI-assisted vulnerability discovery. Phishing as an initial access method climbed from 7% to 23%, partly thanks to generative AI producing convincing, personalised messages, even though social engineering overall fell from 15% to 7% of incidents.

Why it Matters

As a security professional, it's easy to be skeptical of the hype and uncertainty around AI. But if you look at the numbers from real incidents, the tried and tested methods attackers already use are now running much faster than many organizations' current cybersecurity responses can match.

Defenders have always relied on time to detect, investigate and respond before an attacker acted. AI is now eroding that buffer from both ends, with attackers finding entry points quicker, and escalating rapidly once inside. The same picture is reflected in the exploitation timelines of novel vulnerabilities. The Zero Day Clock puts mean time to exploit at around eight hours in 2026, compared with 56 days in 2024.

Faster detection and response still matter, but a program that only starts when an incident is detected is inherently reactive. That is the case for preemptive cybersecurity, the approach of identifying and reducing exploitable exposure before attackers can use it.

What this Means for Practitioners

Ensure you have a continuous and comprehensive view of your public-facing apps, as they are now involved in almost a quarter of incidents. Understand what attackers can reach, not just what exists on your attack surface.

Confirm which exposures can really be exploited in your environment, then prioritize remediation based on observed attacker activity rather than severity scores alone.

Close the identity gaps. Microsoft calls out phishing-resistant MFA, tiered administration and tighter privileged access to limit standing access.

Assume minutes, not days. Ensure high-risk external exposures and attack paths are identified continuously, rather than relying on periodic assessments.

What this Means for Security Leaders

Put greater weight on prevention. Detection and response remain essential, but when attackers can compress parts of the attack lifecycle from days to minutes, there is less time to react once they gain access. Stress-test whether your escalation paths and response processes can keep pace.

Measure the exposure window, not the size of the backlog. Look at how long validated exploitable exposures remain open, as they can now be weaponized within hours.

Plan for prevention to become a larger part of the security mix. Gartner expects preemptive solutions to account for 50% of IT security spending by 2030, up from under 5% in 2024. Consider how prevention fits alongside existing detection and response investments.

Discover More

How Modern ASM Uncovers Hidden Risks in Real Time

Real-time asset discovery is no longer a luxury. It is the baseline requirement for risk reduction. Organizations must identify new systems the moment they become accessible, not days or weeks later. In this blog, learn how the traditional perimeter has expanded, why legacy tools miss critical exposures, and how modern Attack Surface Management can help organizations to uncover hidden risks in real time. Read more.

The Preemptive Cybersecurity Handbook

This week we've launched "The Preemptive Cybersecurity Handbook". It's a practical guide to a different way of thinking about security: understanding where you're exposed, seeing your organization through an attacker's eyes, and taking action before threats become incidents. Download and read the book for free at the link below, and find out how to put preemptive cybersecurity into action for your organization. Read more.

Weekly News Digest

Teenager Suspected of Leading KillSec Ransomware Group as Law Enforcement Seizes Servers and Leak Site

Operation KillSwitch, which was led by German authorities, resulted in 110 terabytes of data being secured. KillSec began operating in 2024 and is linked to approximately 1000 attacks worldwide. The group posted its latest victim to its leak site on September 18th, just 12 days before law enforcement action took place. Three arrests were made and five servers used to manage the group’s activities and store stolen data were seized, as well as multiple domains operated by KillSec.

ShinyHunters Hacker in FBI Data Theft Detained in Jordan, Cooperating with Bureau, Sources Say

Saif al-Din Khader, who goes by the alias “Rey” and is believed to be a member of ShinyHunters, was taken into custody in Jordan. Reports indicate he is actively assisting the FBI and international authorities by providing intelligence to help pinpoint and apprehend his co-conspirators. His detention coincides with disruption to the group’s dark web extortion platform, and comes shortly after the arrest of another suspected ShinyHunters operator in the Netherlands.

Warlock Ransomware Attackers Hit Water and Telecom Operators

Recent attacks involving the Warlock ransomware group show a growing threat to critical infrastructure, with attackers targeting organisations including a water utility and telecommunications provider. The China-linked group is continuing to exploit vulnerabilities in Microsoft SharePoint to gain access before disabling security software and deploying ransomware across multiple systems. The activity highlights how unpatched vulnerabilities and the misuse of legitimate tools can allow attackers to move quickly through networks and disrupt essential services.

‍

Lizzie Clark

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

October 7, 2026

Introducing The Preemptive Cybersecurity Handbook

October 1, 2026

Beacon: Citrix confirms two NetScaler RCE zero-days exploited in attacks

September 24, 2026

Beacon: ShinyHunters Hacks Cl0p Leak Site

September 22, 2026

Sentinel integration for Searchlight Threat – Monitor

September 22, 2026

Reduce false positives with Email Format Validation

September 22, 2026

New Company Dashboard in Searchlight Threat – Monitor

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient