What happened
Microsoft's annual flagship threat-intelligence report, released 1 October 2026, argues that 'AI is changing the physics of cybersecurity': attack timelines are compressing, agentic systems are automating larger parts of the attack chain, and vulnerability volume is accelerating — 'Nearly 40,000 CVEs were published in the first half of 2026, putting the year on track to roughly double,' with publicly disclosed CVEs 'projected to reach a record 72,000 in 2026.' Governments were the most-impacted sector, 'accounting for 27% of observed activity, up from 17% in 2025,' while phishing rose to 23% of observed intrusions (from 7%) and '52.2% of intrusions involving valid accounts resulted in additional credential theft.' The report surveys the July 2025–June 2026 period and covers the threat landscape, cybercrime, resilience, and securing AI/agents (agent identity, prompt injection, memory, attribution, revocation) as an interconnected enterprise problem.
Why it matters
This is the authoritative annual baseline for any board or CISO setting enterprise AI-security and cyber-resilience posture — it quantifies how AI both accelerates adversary operations and compresses defender reaction windows, and frames AI security as an enterprise-systemic issue rather than a model-only one.
Action needed
Brief the board on the compressed-attack-window finding and map the report's agent-identity and prompt-injection control areas onto your AI production inventory before year-end.