i
DATAIST
News · 2026-08-31

Microsoft Defender acts in 128 seconds, patching still takes 43 days

@neuronium_ai @neuronium_ai

Microsoft Defender cut an infected machine off a corporate network 128 seconds after the first alert. The median company now needs 43 days to fully patch a vulnerability attackers are already exploiting. Both numbers belong to the same year, and the distance between them has almost nothing to do with software. The 128 seconds were possible because someone, months before the incident, signed a policy letting the product act without asking a human first. Authorization, not capability, is what separates the two figures — and it is the one input an attacker never has to procure.

Cover: Microsoft Defender acts in 128 seconds, patching still takes 43 days

Microsoft Defender cut an infected machine off a corporate network 128 seconds after the first alert. The median company now needs 43 days to fully patch a vulnerability attackers are already exploiting. Both numbers belong to the same year, and the distance between them has almost nothing to do with software. The 128 seconds were possible because someone, months before the incident, signed a policy letting the product act without asking a human first. Authorization, not capability, is what separates the two figures — and it is the one input an attacker never has to procure.

Verizon has been counting breaches for 19 years. This year, for the first time, the most common way in was not a stolen password but an unpatched vulnerability: 31% of initial intrusions, against 20% a year earlier. Those are precisely the weaknesses that cheaper, AI-assisted attacks can work through at greater volume.

The remediation side moved the wrong way at the same time. Scanning data from 13,000 organizations puts the median time to fully deploy a fix for a vulnerability already under attack at 43 days, up from 32. Of the vulnerabilities on the government's known-exploited list, only 26% were fully remediated, down from 38% the year before. Both measures deteriorated inside a single year. That is the part worth sitting with: the problem is not that defenders lack a list of what to fix. The list is public and curated. What fails to arrive is the fix.

The asymmetry underneath is structural. Software scales worldwide from one release. Security fixes have to be installed company by company, change window by change window. Both sides draw on the same tool market; only one of them can act without additional permissions.

Which is what makes the QNET case instructive. In August, Microsoft published a description of an intrusion at the direct-sales company, which runs a small security team. The attacker used an already installed and trusted Windows utility to load malicious code. Defender disconnected the machine from the network. From first alert to forced isolation: 128 seconds. The analyst arrived to an already isolated node. This is Microsoft describing its own product, and should be read as such — but the capability is documented rather than implied: Defender independently disables accounts, isolates devices and revokes sessions when its confidence passes a set threshold of 99%.

The theoretical case for the defender is not weak. Lennart Maschmeyer, writing in International Security, argues that AI can help the defense, because a successful attack requires creative deception while effective defense requires pattern recognition — and machines are good at patterns. Anthropic's own account data points the same way: among 832 blocked accounts, 84.4% used AI to evade detection, and only 6.5% to move from one system to another. Evasion is not intrusion.

The worst cases, though, point elsewhere. The groups Anthropic rated highest-risk most often used AI after they were already inside a network, and the share of groups the company assigned a medium or higher risk level rose from 33% to 56% in a year. Meanwhile the capability numbers in circulation read stronger than the experiments that produced them. A model crashed the Windows kernel in 31 minutes in one test. Two researchers built exploits for vulnerabilities in 14 open-source packages at roughly a dollar each. Both were controlled demonstrations against targets handed to the model in advance, not intrusions an attacker carried out unaided. The honest summary is that AI currently makes attackers cheaper and quieter, not smarter about getting in.

Offense faces its own permission layer, imposed by vendors. OpenAI grants access to its Daybreak cyber models only after approval and identity verification, and since 1 September individual accounts require hardware keys. Approval gates exist on both sides of this market. The difference is that on the attacker's side one person signs, and on the defender's side the signature travels through budget, legal and a change window.

Here is my read of where this actually goes. Every serious conversation about AI in corporate security is a conversation about pre-approved action lists, and almost nobody is holding it in those terms. The 128 seconds at QNET did not come from a model; they came from a decision, made months earlier, that a machine could unplug a laptop without asking. Extending that decision from laptops to servers, payments, suppliers and production lines is the entire project, and it is a governance project, not a procurement one. It is also genuinely hard: when an autonomous agent is wrong, the business stops, not the attacker — and such a system can already be steered through a single web page. If defensive features in 2027 still work on a propose-and-wait model, then the authority never moved to the machine, whatever the product roadmaps said.

The pressure to move it may come from insurers rather than legislators, and that is the most under-covered thread here. Their lever is not the price of a policy but whether coverage exists at all. The precedent is clean: after 11 September, the Insurance Services Office asked states to exclude terrorism from commercial insurance, and 45 agreed. Reinsurers pulled back or exited, coverage became expensive or unavailable, and in 2002 Congress passed the Terrorism Risk Insurance Act. In January 2026, the same organization issued generative-AI exclusions for general liability, and several carriers have begun applying them. The consequences so far are smaller, and insurance analysts are still working out how businesses actually use AI. But if the practice spreads, the excluded risk attaches to the companies deploying AI hardest — the fastest adopters become the least insurable clients. Aon, for its part, describes a soft cyber market: falling prices and rising limits for well-managed risks, and no sign that AI has changed pricing principles in commercial insurance broadly. Which is the point. Watch the exclusions, not the premiums.

Boards are being pulled the same way by disclosure rules. Under the SEC's 2023 cybersecurity rules, US listed companies describe board oversight of cyber risk in the annual 10-K and must report a material incident within four business days of judging it material. Europe went further: its operational resilience rules took effect on 17 January 2025 and require covered financial firms to keep operating through disruption. There is no honest single number answering "how protected are we." There is an answerable question — whether staff can keep shipping tomorrow if the intrusion happens tonight. If boards in a few years are still reporting oversight rather than recovery times, only the paperwork will have changed.

Underneath all of it sits equipment nobody can replace on a three-year cycle. Windows 10 stopped receiving security updates on 14 October 2025; nothing broke, but machines that were fine on Monday required paid extended support on Tuesday. AI did not cause that transition, though the mechanism it illustrates is the one that matters, because cheaper attacks increasingly land on medical imaging systems, factory controllers and devices from vendors that no longer exist. Regulators are trying to force the hardest case into the open: under section 524B of the FD&C Act, makers of internet-connected medical devices must plan post-market vulnerability remediation, ship patches and list the software components inside the device. The FDA has expected full compliance since October 2023, and a submission missing that information can be held at initial review. The rule covers new devices, not installed ones — so a security requirement turns into a purchasing decision, while the largest exposure stays with equipment already running. ISACA calls the accumulated legacy risk security debt. As support deadlines keep arriving, the cost migrates from the IT budget into the capital plan, unless a company keeps buying extended support and holds it in operating expense.

The intuitive picture pits big companies against small ones, and the data does not support it. In September 2025, the US Treasury's Office of Financial Research assessed cyber risk by company size using CyberCube-based ratings and found a U-shaped curve. The smallest firms do better than expected, mainly because they hold too little of value to ransom. The low point is mid-sized firms with revenue between $1 million and $10 million: rich enough to attract attackers, in OFR's reading, and often without the resources to defend themselves properly. The analysis predates widespread AI, which makes it more useful, not less — it maps where cheaper attacks will go.

And that is where the two halves of this story meet. Large companies can build their own defenses. Firms in the trough of the curve will rent theirs from Microsoft, Google, Amazon, CrowdStrike or Palo Alto Networks. For each of them individually, that solves the speed problem: they buy someone else's 128 seconds. Collectively, it concentrates the entire mid-market behind a handful of update channels — and GAO counted nearly 18,000 customers on the last one that was compromised, at SolarWinds, from which the attacker picked a much smaller set of valuable targets. The concentration is what made the operation worth running. Closing the speed gap and building that concentration are the same purchase.