DKDKCISSPSearch
AI SecurityDEVELOPING

Microsoft: AI Cuts Post-Compromise Attack Time to Minutes

The tech giant said that attackers are getting to the advantages of AI first, and the pressure is now on defenders to adapt quickly to close the gap.

DKCISSP News DeskInfosecurity Magazine2 Oct 2026, 7:45 pm
Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace.

Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist.

Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling development teams to move from vulnerability detection to a verified fix without manual triage.

In a subsequent analysis , Bitget said the attackers exploited the flaw to obtain high-level internal credentials and use them to issue fraudulent withdrawal commands to the wallet system and initiate "abnormal transfers that bypassed existing risk controls." Bitget has since notified the relevant third-party vendor and disabled the affected functionality pending completion of a fix.

This link directs the user to a malicious Microsoft Software Installer (MSI) which is used to deploy a legitimate Canon-signed application the attackers have used to sideload malicious code, this ultimately establishes persistence on the machine and delivers remote access trojan (RAT) malware .

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.

Microsoft says AI can also help threat actors automate larger portions of an attack chain with limited human intervention, while giving less experienced cybercriminals access to capabilities that previously required more skill.

In addition to vulnerability research, attackers are using AI to generate customized malware and accelerate post-compromise activities such as data exfiltration, secret discovery, and lateral movement from days to minutes.

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.

Two malicious Custom GPTs within ChatGPT were used to direct victims to a ClickFix website that spread remote access trojan (RAT) malware, Huntress reported Monday.

What happened

Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace.

Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist.

What changed

Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling development teams to move from vulnerability detection to a verified fix without manual triage.

In a subsequent analysis , Bitget said the attackers exploited the flaw to obtain high-level internal credentials and use them to issue fraudulent withdrawal commands to the wallet system and initiate "abnormal transfers that bypassed existing risk controls." Bitget has since notified the relevant third-party vendor and disabled the affected functionality pending completion of a fix.

Who is affected

This link directs the user to a malicious Microsoft Software Installer (MSI) which is used to deploy a legitimate Canon-signed application the attackers have used to sideload malicious code, this ultimately establishes persistence on the machine and delivers remote access trojan (RAT) malware .

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.

Why it matters

Microsoft says AI can also help threat actors automate larger portions of an attack chain with limited human intervention, while giving less experienced cybercriminals access to capabilities that previously required more skill.

In addition to vulnerability research, attackers are using AI to generate customized malware and accelerate post-compromise activities such as data exfiltration, secret discovery, and lateral movement from days to minutes.

Technical details

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.

Two malicious Custom GPTs within ChatGPT were used to direct victims to a ClickFix website that spread remote access trojan (RAT) malware, Huntress reported Monday.

AI tools are also frequently deployed to generate custom malware for attacks.

Response

On top of that, browser controls can help block known phishing destinations, restrict access to unapproved web applications, and stop the attack earlier.

Browser controls can stop the attack before host execution by blocking the malicious page, restricting clipboard access, or limiting risky browser actions.

What security teams should do

Well-prepared and well-funded adversaries may be able to stockpile large numbers of zero-day vulnerabilities discovered through such means." Microsoft also says the median time between vulnerability discovery in the wild and weaponization has fallen "well below 24 hours," further limiting the time organizations have to patch exposed systems before they are exploited.

What remains unknown

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token.

Attribution

Infosecurity Magazine: The tech giant said that attackers are getting to the advantages of AI first, and the pressure is now on defenders to adapt quickly to close the gap.

BleepingComputer: Article written by Andrius Buinovskis, VP of product strategy at NordLayer EDR remains necessary when attackers execute code on the host.

Help Net Security: Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up.

The Hacker News: The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 amAI Threats Top Cybersecurity Preparedness Gap, PwC FindsInfosecurity Magazine · 1 Oct 2026, 3:00 pm