Microsoft has revealed that its systems analyze more than 100 trillion security signals per day , a figure that highlights the rapid escalation of attacks leveraging Artificial Intelligence (AI) . The company’s “ Microsoft Digital Defense Report 2025 ” warns that AI has become a double-edged sword : a defense tool and, at the same time, a weapon in the hands of cybercriminals.

Artificial Intelligence at the center of cyberwarfare
“We are living in a defining moment in cybersecurity,” said Amy Hogan-Burney, Microsoft’s vice president of security and customer trust. As she explained, the speed of digital transformation, combined with new capabilities of AI, is creating a new class of risks that threaten both economic stability and individual security.
See also: New tech support scam abuses Microsoft brand
The company notes that attackers are now leveraging generative AI to automate phishing attacks, create realistic fake identities , and discover vulnerabilities faster than humans can fix them.
The rise of standalone malware
One of the most worrying developments is the emergence of so-called “autonomous malware” — programs that use machine learning algorithms to adapt their behavior in real time. These systems can change infection routes, mimic human actions, and evade traditional security filters.
At the same time, AI platforms themselves have become targets. Attackers are attempting to poison training data or manipulate models via prompt injection , with the aim of stealing sensitive information or triggering unwanted actions.

Microsoft's answer: Defense with AI
Microsoft is now leveraging AI-driven defenses across its product portfolio, from Azure and Defender to its enterprise suites. According to the company, the integration of AI has reduced detection and response times from hours to seconds, enabling immediate threat isolation.
However, the report highlights that AI is empowering both attackers and defenders, resulting in a never-ending arms race. Organizations are being urged to adopt more agile strategies as attacks now evolve automatically and spread rapidly in cloud environments.
Cyber threat statistics for 2025
Identity theft remains the top attack vector. Phishing and social engineering accounted for 28% of incidents , while 18% came from old or outdated systems .
See also: Microsoft revokes 200 certificates used in ransomware attacks
Despite the clear effectiveness of multi-factor authentication (MFA) — which blocks 99% of unauthorized attempts — Microsoft points out that adoption rates remain low, especially in smaller businesses.
Another worrying phenomenon is the explosion of infostealers, software that collects credentials and sells them on the dark web, allowing other attackers to carry out secondary attacks with minimal effort.
The most targeted countries and sectors
Between January and June 2025, the United States accounted for 24.8% of attacks , followed by the United Kingdom (5.6%) , Israel (3.5%) , and Germany (3.3%) . Government agencies , IT providers , and research institutions accounted for nearly 45% of incidents , confirming that attacks are now strategic in nature .
Meanwhile, ransomware remains a major threat. Over 40% of incidents involve hybrid cloud environments, with a global shipping companynarrowly avoiding a disaster when the attack was stopped just 68 seconds after launch.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: North Korean hackers use EtherHiding to hide malware in Blockchain Smart Contracts

Five critical steps for leaders
Microsoft recommends five strategic moves to strengthen cyber resilience:
- Addressing cybersecurity as an operational risk at board level.
- Enforce phishing-resistant MFA.
- Mapping and monitoring all workloads in the cloud.
- Participation in threat information sharing.
- Risk management planning for AI and quantum technologies.
The message of the new era
The Microsoft Digital Defense Report sends a clear message: security is no longer static, but evolving. As Artificial Intelligence transforms every aspect of society and the economy, resilience, collaboration, and proactive action are the three pillars of defense against a cyberspace that is changing faster than ever.
