Attackers are getting more from AI than defenders, and the patch window has collapsed to under a day.
What happened
Microsoft's 2026 Digital Defense Report, covered by BleepingComputer on 1 October, says attackers are currently getting more from AI than defenders. The operational line: median time from vulnerability discovery in the wild to weaponization is now well below 24 hours. Microsoft expects a multi-year spike in known but unpatched flaws.
Who is affected
- Anyone still running a weekly patch cycle on edge devices
- Internet-facing apps where "next maintenance window" means several days
What to do now
- Treat internet-facing appliances and apps as same-day patch items when a fix or a workaround exists.
- If the fix is not out, the workaround is the control. Waiting for the weekly change window is the exposure.
Source: BleepingComputer on Microsoft's 2026 Digital Defense Report
Also on the blog
- GitLab AI Gateway sandbox escape is a 9.9, patches are out
- FortiMail zero-day is exploited, and most fixes are not shipped
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.