Every year, the Microsoft Digital Defense Report gives us an opportunity to step back from individual threats and look broadly at what Microsoft’s security and threat intelligence teams are seeing. Today, we released the 2026 Report, which reflects a security environment that continues to grow more interconnected.
We see that across the report. Threat activity can span infrastructure, identities, applications, cloud environments, and software supply chains. AI systems and agents increasingly interact with data, tools, and business systems. And activity that looks incomplete in one part of an environment can become clearer when separate signals are considered together. That makes the connections across an environment increasingly relevant to how we understand both cyberthreats and defense.
The pace of change also matters. AI models are becoming more capable, automation is expanding, and new connections are forming across the systems organizations rely on. These developments can change the speed and scale of security activity even as the underlying security fundamentals remain familiar.
Several findings in this year’s report illustrate that.
AI in the threat landscape
Threat actors are incorporating AI into reconnaissance, social engineering, malware and exploit development, and post-compromise activity. For now, much of their use remains focused on specific parts of existing attack workflows, even as more advanced applications of AI continue to develop.
AI can give threat actors greater speed, scale, and ability to tailor activity more efficiently. We see that in social engineering, where AI can make campaigns more targeted, and in technical work, where automation can compress parts of the attack process. The underlying methods often remain familiar. People, identities, exposed systems, and trusted access continue to feature prominently in the threat activity Microsoft observes.
AI is also becoming more connected to the systems and processes organizations already rely on. That brings another dimension to the security work.
Securing AI as part of the enterprise
Agents are a good example of these observations. They can interact with enterprise data, applications, APIs, and tools, with different levels of access and autonomy depending on how they are designed and deployed. Those connections are what allow agents to perform useful work, and they are also part of what security teams need to understand.
That makes it increasingly important to look at AI as part of a broader system. A model may be one component, but its security also depends on the data it can reach, the tools it can use, the identities and permissions involved, and the infrastructure and services around it.
The report looks at agent identity, appropriate access, authentication between agents, attribution, and the ability to revoke access. It also examines security considerations specific to AI, including prompt injection, memory, models and data, agent behavior, and the integrity of software and services around AI systems.
There is a lot we are still learning as these technologies develop. Security teams do have a strong foundation to build from. Identity and authorization, data protection, least privilege, monitoring, testing, and secure software development all remain relevant. AI puts those disciplines into new systems and increasingly connected workflows.
AI and vulnerability discovery
Advances in the application of AI toward code analysis are making it possible to examine software and identify weaknesses more effectively. That creates new opportunities to find vulnerabilities earlier and strengthen software before weaknesses are exploited. Those same advances can give threat actors more capable tools for vulnerability discovery and exploit development.
This is an important area to watch as capabilities develop. AI is giving defenders new ways to find and address weaknesses while giving cyberattackers new ways to look for them. The work on both sides continues to advance.
Connecting what defenders know
The same interconnectedness that shapes how activity moves across systems also shapes how defenders understand it. Security teams work with information from endpoints, identities, cloud environments, applications, email, networks, and threat intelligence. The report shows why those signals become more useful when they can be considered together. Threat activity spanning several systems may leave a pattern that no individual source shows on its own. In a more connected environment, the ability to relate activity across systems becomes an important part of understanding what is happening and where attention is needed.
The same principle extends beyond an individual organization. Trusted sharing of intelligence and information across organizations and public-private partnerships can connect pieces of activity that no one organization sees on its own.
AI can help with that work. Established techniques and repeatable tasks are increasingly candidates for automation, including bringing relevant information together and giving experienced defenders more capacity for deeper investigation.
The discussion of red teaming in this year’s report captures the balance well. Connecting known information and running established techniques can increasingly be automated. Finding an undocumented attack path, or recognizing how weaknesses that appear unrelated fit together, continues to benefit from experienced operators staying close to the work.
That balance will continue to evolve. There is substantial opportunity to use AI to help defenders work more effectively while preserving the human judgment, context, and expertise that remain essential to security work.
The 2026 Microsoft Digital Defense Report looks across the threat landscape, cybercrime, resilience, and the relationships among technologies, identities, systems, and people. Taken together, those findings give us a broader view of the increasingly interconnected environment security teams are responsible for understanding and protecting.
I encourage you to read the full report for a deeper look at the findings, data, and recommendations from Microsoft’s security and threat intelligence teams.
Read the 2026 Digital Defense Report for the full findings, data, and recommendations.
To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.