Yaamlabs

Threat intel

Microsoft Digital Defense Report 2026: what to change

Phishing tripled as a way in and exploits arrive within a day of discovery. The patch, MFA and exposure changes Microsoft's 2026 report points to.

Microsoft published its 2026 Digital Defense Report on October 1. It covers July 2025 to June 2026 and draws on more than 165 trillion security signals a day. In the intrusions Microsoft's incident responders investigated, phishing was the way in 23% of the time, up from 7% a year earlier, and exploits against public-facing applications rose from 15% to 24%. The median time from a vulnerability being found in the wild to a working exploit is now well below 24 hours.

Set that against remediation. Microsoft puts enterprise remediation of critical external vulnerabilities at 30 to 60 days, so most organisations patch internet-facing systems weeks after attackers can use the bug. If you run anything reachable from the internet, or still let staff sign in with a password plus a code, the report describes how you are most likely to be breached this year.

How the attacks work

The two growing entry points need different fixes. Modern phishing kits such as Tycoon2FA, which the report tracks, aim to steal a working session along with the password. These adversary-in-the-middle (AiTM) kits sit between the user and the real sign-in page, pass the password and the one-time code through, and keep the session cookie the identity provider issues at the end. Push approvals, SMS codes and authenticator codes all fail against this, because the user really does complete MFA. Phishing-resistant methods (FIDO2 security keys, passkeys, Windows Hello for Business, certificate-based authentication) bind the sign-in to the real domain, so a proxy on a lookalike domain gets nothing it can replay.

ClickFix is the other phishing pattern the report counts. A fake error or CAPTCHA page tells the user to press Win+R and paste a command, which the page has already put on the clipboard. Microsoft Defender saw attacker-supplied ClickFix commands run on more than 1.1 million unique devices between February and early May 2026. No exploit is involved: the user runs the malware loader themselves.

Exploits against public-facing applications are a timing problem. Microsoft expects about 72,000 CVEs (Common Vulnerabilities and Exposures, the public IDs for known flaws) in 2026, a record, after nearly 40,000 in the first half alone. With weaponization under a day and remediation at 30 to 60 days, Microsoft expects known, unpatched vulnerabilities to pile up for several years. Old bugs still pay: Zerologon (CVE-2020-1472), the 2020 Netlogon flaw that lets an attacker on the network take over a domain controller, was among the top five CVEs in Microsoft's detection data.

What attackers are doing

Once inside with a valid account, attackers go after more of them. In 52.2% of intrusions that began with valid accounts, they harvested further credentials, and another 18.4% involved active password spray campaigns, where one or two common passwords are tried against many accounts to stay under lockout thresholds.

AI is speeding up every stage. Microsoft says China, Iran, Russia and North Korea all use AI in operations. In controlled tests, frontier models chained 32 attack steps to take full control of a domain. The report also describes JADEPUFFER, first documented in July 2026 as the first confirmed ransomware operation run by an autonomous AI agent; we covered its Azure tradecraft in our JADEPUFFER post. In December 2025 Microsoft found a malicious browser extension with more than 600,000 installs collecting ChatGPT and DeepSeek conversation history, affecting nearly 10,000 organisations.

After Microsoft and law enforcement disrupted the Tycoon2FA phishing-as-a-service platform in March 2026, its activity fell 95% from its November 2025 peak by June. Other kits fill the gap within months, so plan as if the volume will return.

What to do

1. Rewrite the patch SLA for internet-facing systems

A single 30-day target for "critical" no longer matches the threat. Split the SLA by exposure. For anything reachable from the internet (VPN gateways, firewalls, remote access portals, mail servers, web applications), a vulnerability with a public exploit or a CISA Known Exploited Vulnerabilities (KEV) listing should get a mitigation within 24 to 72 hours and a patch within 7 days. These targets are ours; the report does not set them.

Write the mitigation path into the SLA so nobody improvises at 2am: disable the vulnerable feature, block the management interface at the edge, or take the device offline behind a temporary rule. Pre-approve those changes as standard changes so they skip the weekly change board. Internal systems can stay on the monthly cycle, with an exception for domain controllers.

On domain controllers, confirm Netlogon secure channel enforcement is on (it has been the default since the February 2021 update) and check the System log for event IDs 5827, 5828 and 5829, which record vulnerable Netlogon connections that were denied or allowed.

2. Make phishing-resistant MFA the baseline

Microsoft's most urgent recommendation is to treat phishing-resistant MFA and passkeys "not as a security upgrade but as a baseline requirement." In Microsoft Entra ID, create a Conditional Access policy with the grant control Require authentication strength set to the built-in Phishing-resistant MFA strength. Apply it to administrators first, then to everyone, and run it in report-only mode for a week to see who would be blocked.

Until everyone is on passkeys, block the device code flow for users who never need it (Conditional Access, Conditions, Authentication flows). To catch ClickFix, alert on writes to the RunMRU registry key (HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU) that contain powershell, mshta or curl; in Defender advanced hunting that is the DeviceRegistryEvents table. Where users have no business need for the Run dialog, Group Policy can remove it.

3. Know what you expose before attackers do

A one-day exploit window is useless to defenders who do not know which systems are affected. Keep a live inventory of everything reachable from the internet, including forgotten test hosts, vendor appliances and cloud services someone stood up outside IT. External attack surface scanning, Microsoft Defender External Attack Surface Management or an equivalent, should feed the same queue as your vulnerability scanner, with each asset tagged to an owner who can patch it.

4. Check whether you are already affected

  • Password spray. In Entra sign-in logs, filter for ResultType 50126 (invalid username or password) and count distinct accounts per source IP address. One address failing against dozens of accounts in an hour is a spray.
  • Stolen sessions. Look for successful sign-ins from unfamiliar IP addresses or countries shortly after a user clicked a phishing link, and for new inbox rules or MFA methods added right after.
  • Browser extensions. Inventory installed extensions through Intune or Defender Vulnerability Management and remove any that read AI chat sites you have not approved.

If you find a stolen session, revoke the user's sessions, reset the password, remove any MFA method or inbox rule the attacker added, and review OAuth app consents for that account.

Our attack surface management team keeps the inventory and exposure checks running, and our security operations engineers build the spray, session and ClickFix detections described above. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Microsoft 2026 Digital Defense Report, Microsoft Security blog, Help Net Security, Tech Times, Geekzone, Cybersecurity Dive.

Back to the blog, or read this post on the full site.