Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
The tech giant said that attackers are getting to the advantages of AI first, and the pressure is now on defenders to adapt quickly to close the gap.

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace.
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist.
Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling development teams to move from vulnerability detection to a verified fix without manual triage.
In a subsequent analysis , Bitget said the attackers exploited the flaw to obtain high-level internal credentials and use them to issue fraudulent withdrawal commands to the wallet system and initiate "abnormal transfers that bypassed existing risk controls." Bitget has since notified the relevant third-party vendor and disabled the affected functionality pending completion of a fix.
This link directs the user to a malicious Microsoft Software Installer (MSI) which is used to deploy a legitimate Canon-signed application the attackers have used to sideload malicious code, this ultimately establishes persistence on the machine and delivers remote access trojan (RAT) malware .
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.
Microsoft says AI can also help threat actors automate larger portions of an attack chain with limited human intervention, while giving less experienced cybercriminals access to capabilities that previously required more skill.
In addition to vulnerability research, attackers are using AI to generate customized malware and accelerate post-compromise activities such as data exfiltration, secret discovery, and lateral movement from days to minutes.
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.
Two malicious Custom GPTs within ChatGPT were used to direct victims to a ClickFix website that spread remote access trojan (RAT) malware, Huntress reported Monday.
What happened
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace.
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist.
What changed
Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling development teams to move from vulnerability detection to a verified fix without manual triage.
In a subsequent analysis , Bitget said the attackers exploited the flaw to obtain high-level internal credentials and use them to issue fraudulent withdrawal commands to the wallet system and initiate "abnormal transfers that bypassed existing risk controls." Bitget has since notified the relevant third-party vendor and disabled the affected functionality pending completion of a fix.
Who is affected
This link directs the user to a malicious Microsoft Software Installer (MSI) which is used to deploy a legitimate Canon-signed application the attackers have used to sideload malicious code, this ultimately establishes persistence on the machine and delivers remote access trojan (RAT) malware .
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.
Why it matters
Microsoft says AI can also help threat actors automate larger portions of an attack chain with limited human intervention, while giving less experienced cybercriminals access to capabilities that previously required more skill.
In addition to vulnerability research, attackers are using AI to generate customized malware and accelerate post-compromise activities such as data exfiltration, secret discovery, and lateral movement from days to minutes.
Technical details
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.
Two malicious Custom GPTs within ChatGPT were used to direct victims to a ClickFix website that spread remote access trojan (RAT) malware, Huntress reported Monday.
AI tools are also frequently deployed to generate custom malware for attacks.
Response
On top of that, browser controls can help block known phishing destinations, restrict access to unapproved web applications, and stop the attack earlier.
Browser controls can stop the attack before host execution by blocking the malicious page, restricting clipboard access, or limiting risky browser actions.
What security teams should do
Well-prepared and well-funded adversaries may be able to stockpile large numbers of zero-day vulnerabilities discovered through such means." Microsoft also says the median time between vulnerability discovery in the wild and weaponization has fallen "well below 24 hours," further limiting the time organizations have to patch exposed systems before they are exploited.
What remains unknown
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.
Attribution
Infosecurity Magazine: The tech giant said that attackers are getting to the advantages of AI first, and the pressure is now on defenders to adapt quickly to close the gap.
BleepingComputer: Article written by Andrius Buinovskis, VP of product strategy at NordLayer EDR remains necessary when attackers execute code on the host.
Help Net Security: Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up.
The Hacker News: The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console.
What to watch next
Watch for new exploitation reports and updated indicators of compromise.
Watch for updated vendor guidance and fixed-version details.