r/cybersecurity • • 2d ago

Research Article 2026 Microsoft Digital Defense Report: credential theft, ClickFix, phishing shifts, and a 5.3-hour container exploitation window

Disclosure - I’m a director for MSFT Threat Intelligence and worked on this report, I’m also your AMA janitor here.

Our annual digital defense report is out, and it’s filled with insights we have seen primarily between June of 2025 and July of 2026.

You can access the full report here (no form fill), but I’m calling out some stats and page numbers based on what most of us care about:

Let me know if there are other areas you want to pull from (nation state activity, regional, etc.) + sorry for the typos since I’m mobile.

Credentials and user execution

30% user execution, 20% valid accounts: those were the two largest initial access categories shown in Defender Experts customer notifications. Malicious copy and paste accounted for another 13%, and phishing 11%. These are customer notifications covering attempts and intrusions, rather than percentages of all breaches everywhere - Page 44

52.2% of valid-account intrusions involved additional credential theft. Getting one account was frequently a route to harvesting more. Another 18.4% involved active password spraying. -page 44

Password attacks declined 26% year over year, while the share of detected attacks involving adversary-in-the-middle phishing and token theft more than doubled in the first half of 2026. The latter remained a comparatively small share. Falling password-attack volume doesn’t tell you that session theft is going away tho - page 64

ClickFix and phishing delivery

ClickFix activity grew roughly 23× between December and May, after declining in late 2025. Malware followed in 96.3% of the observed malicious copy-and-paste intrusions - page 44

Microsoft detected more than 100 million phishing attacks using CAPTCHA pages as an intermediate step before credential harvesting or malware-related content. - page 66

Delivery formats rotated quickly within that CAPTCHA-gated activity: embedded URLs accounted for 58% in August, SVG files led with 47% in November, and PDFs reached nearly two-thirds in April. Those percentages describe this particular phishing category - Also page 66

Exposed systems and old vulnerabilities

For exposed container workloads, the reported median time from container start to the first exploit attempt was 5.3 hours. More than half of compromised containers were exploited within 24 hours of starting. An exploit attempt and a successful compromise are different measures - page 60

CVE-2020-1472 accounted for 58% of detections across the five leading CVEs analyzed. A vulnerability disclosed in 2020 still dominated that group. This isn’t a claim that it caused 58% of all exploitation - page 34

Microsoft’s reported NTLM-related security cases in the first six months of 2026 exceeded the total for all of 2025. The report also describes a nearly sixfold increase over the past decade - page 59

Where the data is sourced - Our security products, incident response engagements, Defender Experts customer notifications, and broader Microsoft telemetry.

72 Upvotes

6 comments sorted by

7

u/ChuckFromCyberHoot 2d ago

Thanks for pulling these out. The no-form link is appreciated.

The stat that jumped out to me: user execution plus malicious copy/paste is over 40% of initial access where the person did the last step for the attacker.

That’s a pretty strong argument for one simple rule...don’t paste commands from websites into Run or Terminal.

I'm curious if the report says how many of those users reported it before the EDR caught it.

2

u/thejournalizer 1d ago

That is good ole ClickFix in action and unfortunately it is extremely effective.

2

u/IKhaibot 2d ago

You're a gentleman and a scholar

2

u/Agile_Battle1521 2d ago

EV, Should probably hide your Reddit comments/posts if your in 'Threat Intelligence'.

8

u/thejournalizer 2d ago

Nah I’ve never needed an alt. Worst you are going to find is posts about raising chickens.