Microsoft described AI as an accelerator inside familiar attack chains.
What happened. Microsoft Threat Intelligence said actors were using AI to speed research, improve lures, develop malware, and triage stolen data while humans generally remained in the loop. It also described its March disruption of Tycoon2FA infrastructure.
Impact and confidence
This is provider telemetry and assessment, not a census of all threat activity. It supports a tempo shift more strongly than claims of fully autonomous campaigns.
Defensive takeaway
Shorten identity investigation loops and govern privileged defensive agents. Inventory and auditability matter more as both sides automate routine work.