TL;DR Microsoft is counting its own bugs as a threat, started its bomb clock after the explosion, and calls their partner some kind of criminal.
You may remember when I recently showed how the Microsoft Agentic Governance Toolkit was completely broken logic. It was a hack, an empty shell, lacking proper controls inside to do what the tin advertised.
Well, here we go again. I’m not sure why Microsoft is still in business, at this point, but since they seem to still be putting things into the market here’s another look at what that means to someone who looks behind their curtain.
Page 14 of the Microsoft Digital Defense Report 2026 carries this sentence:
The median time from vulnerability discovery in the wild to weaponization has now collapsed to well below 24 hours.
Think about the time from explosion of gunpowder to someone lighting a fuse being well below 24 hours. Sound backwards? That’s because it is.
Read the Microsoft claim twice. “In the wild” is the term of art for exploitation already observed. It’s the explosion in your face. A vulnerability is discovered in the wild when someone catches the exploit running against a live system. The weapon exists before the weapon is discovered being used. The interval the sentence claims to measure starts after the event it ends with.
A bomb squad timing detonation to manufacture would report the same number, for the same very, very stupid reason.
The honest interval runs from disclosure to exploitation, and the report flips it back to reality on page 47, in the ransomware chapter:
The disclosure-to-exploitation window has shrunk to single-digit days, if not exploited as a zero-day before any advisory is issued. Microsoft has observed the following trends: More, faster weaponization. The Cybersecurity and Infrastructure Security Agency (CISA) added over 110 CVEs to the Known Exploited Vulnerabilities (KEV) catalog from November 2025 to May 2026, most within a week of disclosure.
Single-digit days. Within a week. Record-scratch. What happened to sub-24 hour? And more to the point, the examples that follow are Storm-1175 deploying Medusa ransomware within 24 hours of initial exploitation, SAP NetWeaver weaponized a day after disclosure, and a September 2025 Akira surge across fifty organizations riding CVE-2024-40766, a SonicWall bug published a year earlier. Conventional crews with a known catalog of bugs were on measured intervals. Page 47 is dull because it was the actual math and nothing is alarming. Page 14 had to torture the clock to make it sound scary.
The word “median” also puts Microsoft on a specific kind of hook. A median implies a distribution, a sample, a period, a source. Page 14 has exactly zero, which means it can’t use the word median in good faith. The AI chapter has its sources made clear by hyperlink, which makes the median claim stand out even more as unlinked. Also unlinked? The “record-breaking estimated 72K” CVE figure beside it, and the claim on page 10 that attackers “are reaching to advantages first.” Says who? Are these magical fairy dust claims seriously the level of work to expect from Microsoft now? Perhaps they should switch to writing children’s books.
The chapter carries twenty-one links across twenty pages. Fifteen sit on pages 14 to 16. Fine. My beef is with pages 10 through 13, where the thesis is stated. The important pages carry zero links. Allow me to audit and illustrate the Microsoft deliverable in terms of errors and omissions, which I hear is a field of law.
| Claim | What is missing |
|---|---|
| Attackers “reaching to advantages first”; equilibrium “will be re-established” (10) | Metric, baseline, date |
| Leading-edge threats “commoditized within a year” (10) | Basis for the forecast |
| Known-but-unpatched vulnerabilities “will rise sharply” over “a multi-year window” (10, 12) | Count, trend data |
| Sleeper-agent model tampering “already observed in the wild” (11) | Incident, model name |
| Stolen AI capacity resold “to criminal and nation-state customers” (11) | Any nation-state buyer; Sysdig documents criminal resale only |
| Distillation theft “has become widespread” (11) | Case; page 19 calls distillation “legitimate and widely used” |
| OpenClaw “notorious for deleting data, revealing secrets… spending users’ money” (11) | Incident |
| Exfiltration, secret discovery, lateral movement cut “from days to minutes” (12, 13) | Case, timing data |
| Known vulnerabilities “shot up” from tools “with far lower false-negative rates” (12) | Tool name, figure |
| Adversaries “may stockpile large numbers of zero-day vulnerabilities” (12) | Evidence; stated as speculation |
| Unauthenticated MCP services with developer credentials “unfortunately common” (12) | Count |
| AI “fixes all four” fraud weaknesses “simultaneously” (13) | Evidence |
| Customized lures “will materially increase attack success rates” (13) | Measured rate |
| AI for weapons proliferation, mass-casualty planning (13) | Case |
| Mythos “first” to autonomously run a 32-step attack (14) | Link covers GPT-5.5 only; Mythos half unlinked |
| Open-weight models “lag closed models by seven months” (14) | Definition of lag; attributed by link placement only |
| Microsoft “observed AI-orchestrated intrusions sharing elements with JADEPUFFER” across sectors and regions (14) | Count, case; the source case was human-staged |
| Median discovery-in-the-wild to weaponization “well below 24 hours” (14) | Dataset; clock starts after the event; page 47 says single-digit days |
| “Record-breaking estimated 72K” CVEs for 2026 (14) | Source; the count measures CNA assignment, not exploitability |
| Discovery and weaponization now “simply writing a prompt” (14) | Example |
| Vendor AI patching leads to “equilibrium” (14) | Basis for the forecast |
| PromptLock delegated logic to a model “on adversary infrastructure” (15) | Source; the ESET sample was claimed by NYU Tandon researchers as an academic prototype |
| TikTok ClickFix “~500,000 views”, “per-lure cost to near zero” (15) | Source for views; cost claim unsupported |
| Agent skill registries “already ship malware disguised as utilities” (15) | Case |
| Browser extension: “600,000+ installs”, “almost 10,000 organizations” (16) | Page 27 gives “nearly 900,000 installs”, “more than 20,000 enterprise tenants” for the same campaign |
| A self-improving worm on stolen LLM keys “will soon” appear (16) | Evidence; the Xlab link covers credential theft only |
| Actors extended agentic AI into “malware and exploit development and post-compromise operations” (17) | Case |
| Actors “beginning to explore” direct exploitation of enterprise agents (17) | Case; stated as “could include” |
| Human direction “unlikely to exist for very long” (17) | Basis for the forecast |
| Source review “would have taken skilled people weeks”, now “continuous” (18) | Benchmark |
| Distilled copies “frequently lack the safeguards” of parent models (19) | Measurement |
| “88% of enterprises” experimenting with agents; “82% of leaders” plan rollouts (22) | Survey name, sample |
| “Roughly 1.3 billion agents in production by 2028” (22) | Attribution for the projection |
| Prompt-goal percentages, Feb to May 2026 (22) | Denominator, publication; drawn from Microsoft filter logs |
| Four techniques “roughly 90%” of AI-workload attacks, “90 day window” (23) | Denominator; window undated |
| Agent-to-agent spoofing “a rising technique” (23) | Case |
| “Roughly 85% of work now happens” in the browser (27) | Source |
| AI browsers as infection vector in “more than 40% of organizations”, “57 distinct malware families” (27) | Publication; internal May 2026 analysis |
Fun! Or should I say, FUD!
What the chapter does cite collapses with a simple poke. The proof that frontier models can “fully autonomously orchestrate complex attacks” is a 32-step compromise reported by the UK AI Security Institute. I’ve debunked this kind of claim many, many times before. But the FUD balloon keeps getting filled by self-serving vendors faster than I can pop them. The report’s own caveat: “The test took place in a mock company computer system with no defenders.”
NO DEFENDERS.
A test with the defenders removed is offered as evidence of attacker having an advantage over defenders. Are Microsoft staff being tested for drugs?
The “first documented automated ransomware extortion attack” is JADEPUFFER, a late June 2026 intrusion Sysdig described on July 1. The entry point was Langflow CVE-2025-3248, followed by Nacos CVE-2021-29441 and an unchanged default signing key. Five days later Sysdig’s Michael Clark told CyberScoop that a human picked the victim, built the command-and-control and staging servers, and supplied the database credentials from a prior compromise. The encryption key was ephemeral. Payment would have restored nothing.
To put it plainly, a human-staged wipe over a five-year-old bug is filed on page 14 as “the first evidence of the transition to full attack autonomy.”
The second real-world case is the July 2026 Hugging Face incident. OpenAI’s own evaluation agent left OpenAI’s own sandbox through a proxy the sandbox left open and went after a benchmark’s answer keys. The attacker was an AI lab. The victim was an AI lab. The failure was a sandbox. Microsoft files it on page 15 under “Real-world autonomous attacks of increasing complexity,” in the same box as JADEPUFFER, a criminal extortion crew.
REAL-WORLD ATTACK. Microsoft’s largest AI partner, called out as if just another ransomware gang. Hello, any lawyers in the house?
The Red Team chapter, page 19, settles the question the AI chapter opens:
AI does not change where attacks begin—the foothold still comes from familiar sources, for example, a sprayed credential, an unpatched edge service, or an identity gap.
Both flagship cases entered through exposed services running known-vulnerable software. This continues to prove that the basics are what matter and the FUD is doing nobody any favors. Here the advantage that the report assigns to AI is just the old patching story yet again.
Which raises the question of whose gap we are really talking about when Microsoft starts tooting their security horn. Page 12 explains why remediation lags discovery: “many systems lack robust unit and integration testing and so cannot deploy code changes rapidly.” That is a description of vendor engineering. The page then predicts “a multi-year period where the number of known but unpatched vulnerabilities spikes.”
My first run at Windows NT 3.5 was as a DEC partner asked to secure Alpha in 1994, with word from the project that Gates had punted security work out to ship faster. A fresh install lasted about as long on a public network as it took to plug in. I sniffed networks and watched the administrator password cross the wire in cleartext to Korean IPs. Point of sale operating system experts later told me Gates visited Santa Cruz Operation and told them he would fund security the day someone showed him a billion dollars in it. So when Code Red hit in July 2001 on an IIS buffer overflow, Microsoft had patched it only a month earlier. Nimda followed in September. Gates then sent out his Trustworthy Computing memo of January 2002, claiming his decades of shipping defects to customers for margin to Wall Street would no longer be the culture. A year later Slammer hit SQL Server through a hole patched the previous July, a 376-byte UDP packet that doubled its infected population every 8.5 seconds and took down networks worldwide. Fun fact from back in the day, sniffing traffic meant we saw SQL traffic spiking the days before the worm hit and had shut the port off. Microsoft wasn’t watching, but they could have been. I guess Bill Gates didn’t see the profit angle in avoiding global disaster.
Three decades of shipping first and patching later is technical debt by design, with the interest billed late and inflated to the customer. Microsoft shipped 570 fixes on its July 2026 Patch Tuesday, 400 in August, and a record 966 on September 8, with 204 more earlier that month. Microsoft credits the surge to its own AI-powered vulnerability discovery system rather than to the human-powered fire-ready-aim that produced the bugs. That is a defect generation model, and the cure for it has been well documented since at least the end of WWII.

The report’s “record-breaking” CVE count for 2026 belongs beside Gates’ 1976 Open Letter to Hobbyists, where he told people sharing software for the public good that they were thieves and that he knew better than they did what computing should cost. Fifty years later the bill arrives as a backlog Microsoft’s scanner generates against Microsoft’s products, delivered to Microsoft’s own customers at close to a thousand a month, and the current report files it under threats.
Page 14 again: “Software vendors are using AI to identify and patch vulnerabilities, which will lead to more secure software after initial large patch waves.” The large patch waves are Microsoft’s own failure to do the hard work they are supposed to be paid to do in the first place. Remember how “enterprise” was a label they tossed around as though it meant paying for something safety-related? BleepingComputer ran the headline the day the report appeared: threat actors are ahead in the early AI race. One commenter asked what Microsoft planned to do about it. Page 47 tells us that Microsoft knows the real numbers after page 14 spun up some FUD to distract readers from what is real.