On October 1, BleepingComputer reported Microsoft's assessment that criminals currently get more from AI than defenders do. Coverage of Microsoft's 2026 security reporting on October 2 also described autonomous ransomware activity and a compressed exploit window measured in hours, against patch cycles still measured in weeks. I used BleepingComputer and the TechTimes write-up of that report.
This is a vendor narrative as much as a measurement. The useful part for me is the time gap, hours versus weeks, not the slogan about a race.
If my own patch lag is still 30 days, that gap is the story. The model names in the Microsoft write-up are not.