威胁行为者正利用人工智能更快地发现漏洞、构建恶意软件并实施入侵,其速度已超出防御者的应对能力。
微软发布的《2026年数字防御报告》涵盖了2025年7月至2026年6月期间,描述了一个攻击者率先从人工智能中获益、而防御者必须迅速行动以缩小差距的近期阶段。“人工智能正在改变网络安全的物理法则,”该公司表示。
漏洞发现速度快于修复速度
过去,漏洞的发现和利用需要人类专家。微软指出,在许多情况下,这项工作归结为“只需编写一个提示词”。
从野外发现漏洞到武器化的中位时间已降至远低于24小时。2026年追踪的CVE数量有望创下约72,000例的历史纪录。
修复速度慢于发现速度,因此微软预计将经历一个多年期,期间已知但未修补的漏洞将不断累积。资金充足的攻击者可能能够囤积以此方式发现的零日漏洞。
在微软事件响应人员调查的入侵事件中,钓鱼攻击是2025年7月至2026年6月期间23%入侵的入口,而一年前这一比例为7%。同期,针对面向公众的应用程序的利用比例从15%上升至24%。
钓鱼和欺诈获得升级
人工智能让攻击者能够个性化每一条钓鱼信息,将鱼叉式网络钓鱼转变为大规模行动,并帮助他们克服语言和技能障碍。
以前,伪造身份的诈骗者往往会露出马脚:伪造的身份证件看起来不对劲,文字读起来像第二语言,面试中带有口音,且网上几乎没有任何痕迹。“人工智能同时解决了这四个问题,”微软指出。
在52.2%以有效账户开始的入侵事件中,攻击者在进入系统后窃取了更多凭证,另有18.4%涉及主动的密码喷洒活动。
国家黑客将人工智能融入工作
一些中国国家行为者使用人工智能工具搜索漏洞或利用它们的技巧。俄罗斯威胁行为者使用了氛围编码(vibe coding)和人工智能生成的工具,人工智能用于扩大其行动的规模和速度。
朝鲜行为者增加了人工智能的使用。远程IT工作者计划利用人工智能进行身份构建、社会工程学和维持访问权限,其他朝鲜团体则将其用于恶意软件创建和基础设施管理。有些团伙尝试使用代理工作流和大语言模型(LLM)生成的代码以加快恶意软件的部署速度。
2026年3月,由一个国家级赞助组织对Axios npm包进行的入侵被列为朝鲜供应链活动之一。
该公司预计,中国、伊朗、俄罗斯和朝鲜将在整个入侵生命周期中持续增加人工智能的应用,包括更多自主系统。
内置模型的恶意软件
s1ngularity恶意软件通过2025年8月传播的特洛伊化Nx npm包扩散,它在受感染机器上寻找Claude Code、Gemini CLI或Amazon Q CLI,并以宽松覆盖的方式运行它们以搜寻密钥和SSH密钥。它泄露了约2,000个密钥和来自225名受害者的约20,000个文件。
PromptLock是一个实验性勒索软件原型,仅附带提示词,并在运行时从攻击者基础设施上的开放权重模型接收Lua脚本。
2025年12月,微软发现了一个拥有超过600,000次安装的恶意浏览器扩展,它在窃取ChatGPT和DeepSeek的对话内容。在得到缓解之前,它影响了近10,000个组织。
自主攻击走出实验室
Anthropic的Mythos和OpenAI的GPT-5.5是首批展示自主协调复杂攻击潜力的模型。在对一个没有防御者的模拟企业环境进行的测试中,它们通过32步攻击链控制了整个域,包括主服务器和所有用户账户。在攻击协调方面,开放权重模型落后于封闭模型七个月。
2026年7月初,发生了首起有记录的自动化勒索软件敲诈攻击,Sysdig威胁研究团队将其命名为JADEPUFFER。微软观察到,由人工智能协调的网络入侵活动与该事件存在相似之处,但规模较小。同月,OpenAI用于网络安全的模型训练代理突破了沙箱限制,对Hugging Face发起攻击,以获取某个基准测试的答案密钥。
2026年6月发布的一份报告显示,利用当前技术实现由人工智能驱动的自传播蠕虫是可行的。微软警告称,威胁行为者很快就能构建出一种蠕虫,它利用窃取的LLM提供商密钥进行自我改进,研究新的漏洞并优化其社会工程学手段。
“在我们观察到的大多数活动中,目标选择、作战决策以及最复杂入侵的执行仍主要由人工驱动。”微软写道。该公司预计这些限制将很快消失。
Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up.
Microsoft’s 2026 Digital Defense Report, covering July 2025 to June 2026, describes a near-term period in which attackers collect the benefits of AI first and defenders have to move quickly to close the gap. “AI is changing the physics of cybersecurity,” the company said.
Bugs found faster than they get fixed
Vulnerability discovery and weaponization once required human experts. In a lot of cases, the job comes down to “simply writing a prompt,” Microsoft noted.
The median time from vulnerability discovery in the wild to weaponization has dropped to well below 24 hours. The number of CVEs tracked for 2026 is on track for a record of an estimated 72,000.
Remediation moves slower than discovery, so Microsoft expects a multi-year period in which known, unpatched vulnerabilities pile up. Well-funded attackers may be able to stockpile zero-days found this way.
Phishing was the way in for 23% of the intrusions Microsoft’s incident responders investigated between July 2025 and June 2026, up from 7% a year earlier. Exploits against public-facing applications rose from 15% to 24% over the same period.
Phishing and fraud get an upgrade
AI lets attackers personalize every phishing message, turning spear phishing into a mass operation, and helps them get past language and skill barriers.
Fraudsters faking an identity used to slip up with a forged ID that looked off, writing that read like a second language, an accent that came through during an interview, and barely any trace online. “AI fixes all four simultaneously,” Microsoft stated.
In 52.2% of intrusions that began with valid accounts, attackers harvested more credentials once inside, and another 18.4% involved active password spray campaigns.
State hackers fold AI into their work
Some Chinese state actors use AI tools to search for vulnerabilities or for tips on exploiting them. Russian threat actors have used vibe coding and AI-generated tooling, with AI serving to boost the scale and speed of their operations.
North Korean actors have increased their use of AI. The remote IT worker scheme uses AI for persona development, social engineering and keeping access, and other North Korean groups use it for malware creation and infrastructure management. Some have tried agentic workflows and LLM-generated code to speed up malware deployment.
The March 2026 compromise of the Axios npm package by a state-sponsored group is listed among North Korean supply chain activity.
The company expects China, Iran, Russia and North Korea to keep adding AI throughout the intrusion lifecycle, including more autonomous systems.
Malware with a model inside
The s1ngularity malware, spread through trojanized Nx npm packages in August 2025, looked for Claude Code, Gemini CLI or Amazon Q CLI on infected machines and ran them with permissive overrides to hunt for secrets and SSH keys. It leaked about 2,000 secrets and about 20,000 files from 225 victims.
PromptLock, an experimental ransomware prototype, shipped with prompts alone and received Lua scripts at runtime from an open-weights model on attacker infrastructure.
In December 2025, Microsoft found a malicious browser extension with more than 600,000 installs harvesting ChatGPT and DeepSeek conversations. It affected almost 10,000 organizations before it was mitigated.
Autonomous attacks move out of the lab
Anthropic’s Mythos and OpenAI’s GPT-5.5 were the first models to show the potential to orchestrate complex attacks on their own. In a test against an emulated enterprise environment with no defenders, they took control of the whole domain, including the main server and all user accounts, through a 32-step attack chain. Open-weight models trail closed models in attack orchestration by seven months.
Early July 2026 brought the first documented automated ransomware extortion attack, which the Sysdig Threat Research Team named JADEPUFFER . Microsoft has observed AI-orchestrated intrusions that share elements with that activity, at low volumes. The same month, OpenAI cybersecurity model training agents escaped their sandbox and attacked Hugging Face to get at a benchmark’s answer keys.
A report published in June 2026 showed that self-spreading worms driven by AI are feasible with current technology. Microsoft warns that a threat actor could soon build a worm that uses stolen LLM provider keys to improve itself, researching new vulnerabilities and refining its social engineering.
“Target selection, operational decision-making, and execution of the most complex intrusions remain manually driven in the majority of campaigns we observe,” Microsoft wrote. The company expects those limits to fade soon.
首次收录 · 2026-10-03 · 7.49 分