“Well below 24 hours” is the phrase Microsoft chose for the median interval between a vulnerability being discovered in the wild and attackers turning it into a working weapon. The wording sits in the company’s 2026 Digital Defense Report, published October 1, and it describes a clock that used to be counted in weeks.
The same report puts the pressure on defenders in plain terms. Remediation, Microsoft writes, is “inherently much slower than discovery,” and the company expects a multi-year stretch in which the number of known but unpatched vulnerabilities spikes. The report also describes Microsoft’s own vantage point as enormous, citing more than 165 trillion security signals processed every day.
The measured interval from discovery in the wild to weaponization
The sentence in the report’s AI threat section reads that the median time from vulnerability discovery in the wild to weaponization “has now collapsed to well below 24 hours,” and it pairs the claim with a forecast of roughly 72,000 Common Vulnerabilities and Exposures tracked for 2026, a record. The full text is in Microsoft’s 2026 Digital Defense Report, and BleepingComputer’s coverage of the report quotes it the same way.
Two details matter for reading it correctly. The starting point is discovery in the wild, not the day a patch ships, and the end point is weaponization, not a confirmed breach. The figure is also a median, which means half of the cases sit above it, so it describes a typical race rather than the slowest or the fastest one. Microsoft does not break out the underlying sample or the exact hour count in the passage quoted by the press, so “well below 24 hours” is the most precise wording the public record supports, and any single-digit-hour figure would be an invention rather than a reading of the report.
Patch-to-exploit counts and the CVE surge
A separate yardstick tracks exploitation after a CVE is published. Cybernews, summarizing VulnCheck’s State of Exploitation report for the first half of 2026, reported that 23.4 percent of vulnerabilities were exploited within 24 hours of CVE publication. That is a share of bugs, measured from a public disclosure date; Microsoft’s figure is a median time, measured from discovery in the wild. The two cannot be swapped for each other, and neither tells a reader how quickly a given company patches, which is the variable that decides whether either number turns into an actual breach.
The volume context is steep. A Brandefense analysis counts 48,185 CVEs published in 2025, so Microsoft’s projected 72,000 for 2026 would be a jump of roughly half in one year. More bugs entering the pipeline while the weaponization median shrinks is the combination that drives the report’s forecast of a growing pile of known but unpatched flaws, since each additional CVE competes for the same limited patching capacity inside a company.
Attackers in the report: China, Russia and North Korea
Microsoft attributes part of the acceleration to artificial intelligence and names three state-linked groups of actors using it. Chinese actors, the report says, use AI tools to hunt for vulnerabilities and learn exploitation techniques while still relying on phishing and remote access trojans. Russian actors employ so-called vibe coding and AI-generated tooling to speed up their attacks. North Korean actors use AI for persona development, social engineering, malware creation and attack infrastructure, including agentic workflows and LLM-generated code.
For sophisticated actors, Microsoft says, AI offers “unprecedented speed, scale, and customization, reducing the attack chain from days to seconds.” The company adds a brake on the alarm: most observed campaigns still retain human direction, even though frontier systems have shown end-to-end autonomy in labs and in early real-world cases.
The speed of individual intrusions shows up elsewhere in Microsoft’s research. In reporting by The Record, Microsoft’s analysis of the Medusa ransomware operation described some intrusions moving from initial access to data theft and ransomware in under a day, although typical Medusa incidents ran five to six days.
The equilibrium Microsoft expects defenders to regain
Microsoft frames the present as a transition. The equilibrium between attackers and defenders, the report says, will probably be re-established eventually, but “in the near term” attackers are reaching their advantages first. One reason it gives for the lag on the defensive side is that many systems lack robust unit and integration testing, which slows the confidence needed to ship a fix without breaking something else in production.
That leaves a measurable gap rather than a slogan, and the report is explicit that the gap is the near-term story: a weaponization median under a day on one side and remediation timelines that Microsoft itself calls much slower on the other. The report does not publish a matching median for how long defenders take to patch, so the width of that gap is still unquantified.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- Amazon’s Prime refunds are rising to $200 as millions more customers become eligible
- A handful of car engines are so tough mechanics say they almost never wear out
- The NSA is again telling phone owners to switch off one location setting
- Supplements now rank as the fifth-leading cause of death from liver disease.