Dive Brief:
- Businesses need to prepare for the ways in which AI is changing the cyberattack landscape, Microsoft warned on Thursday.
- AI is speeding up attacks, making advanced techniques easier and putting stress on systems that organizations have long overlooked, the company said in its annual Digital Defense Report.
- The report also describes nation-state and cybercrime threat actors’ most significant activity from the past year, including their targets and motivations.
Dive Insight:
Microsoft’s report warns defenders that AI is upending the process of guarding against cyberattacks by “reshaping how vulnerabilities are identified, how attacks are developed, how defenders prioritize risk, and how organizations respond to emerging threats.”
The technology “has compressed the security cycle from days to minutes,” according to the report. “Its influence extends far beyond AI systems themselves and into the very fabric of our societies.”
Vulnerability discovery is one of the most visible areas where AI is having a profound impact. In its report, Microsoft said organizations should prepare for “a multi-year period where the number of known but unpatched vulnerabilities spikes” as discovery and exploitation outpace mitigation. The tech giant noted that sophisticated hacking groups, such as those working for national governments, “may be able to stockpile large numbers of zero-day vulnerabilities discovered through such means.”
Beyond discovering flaws, AI is also replacing or augmenting humans in some of the activities required to carry out an attack. Microsoft highlighted Sysdig’s July discovery of the first documented ransomware operation powered entirely by agentic AI. “Microsoft has observed AI-orchestrated intrusions sharing elements with [that] activity,” the company said. “Volumes remain low, though the activity is not confined to a single sector or region.”
One of the best ways organizations can defeat AI-powered attacks is to carefully monitor and lock down their identity assets. “Identity is the primary control plane for defense,” Microsoft said, noting that attackers often abuse elevated privileges and weak passwords. Techniques such as “disciplined identity hygiene” and least-privilege access “remain the best safeguards against cyberattacks,” according to the report.
Data governance is equally important because AI platforms are only as trustworthy as the data on which they rely. “Data protection has always been a key priority,” Microsoft said, “and now that AI systems and agents can reach and act on sensitive information at unprecedented scale, it’s more crucial than ever.”
Microsoft’s other recommendations included protecting AI software supply chains, prioritizing the security of agentic AI systems and evolving detection and response strategies to match the pace of AI.
Beyond AI, the report describes a series of other emerging threats, including compromises of open-source supply chains and attacks on edge devices.
The two most common initial-access means over the past year were the exploitation of vulnerable public-facing applications (24% of incidents) and phishing (23%). In Microsoft’s previous annual report, the abuse of valid accounts was the most common technique, accounting for 17% of incidents.
While new vulnerabilities are disclosed virtually every day, hackers are still focused on years-old flaws that continue to yield the access they need. The five most exploited CVEs, according to Microsoft’s investigations, were a 2020 Netlogon Remote Protocol flaw dubbed “Zerologon,” a 2022 VMware remote code execution vulnerability, a 2021 Microsoft Office RCE flaw, a 2023 Microsoft DHCP RCE vulnerability and a 2020 Microsoft cryptography spoofing flaw.