Microsoft and ENISA, a European Union agency focused on cybersecurity, have released reports that highlight the rising use of phishing, identity theft, and a technique called ClickFix in cyberattacks. These reports also note the growing role of artificial intelligence (AI) in making these attacks faster and more effective. According to the Microsoft Digital Defense Report 2026 and the ENISA Threat Landscape 2026, attackers are increasingly targeting human factors and stolen login details to access systems, with AI helping to speed up these processes. Phishing, a method where attackers trick people into revealing sensitive information, has become the second most common way cyberattacks begin. It increased from 7% to 23% between 2025 and 2026. ENISA adds that 77.8% of social engineering attacks in Europe involve phishing. ClickFix attacks, which trick victims into running harmful commands, have grown 23 times more frequent between December 2025 and May 2026. Microsoft’s findings are based on incident response data from July 2025 to June 2026, while ENISA’s report analyzed 8,257 cyber incidents in the European Union in 2025. ENISA gathered its data from member states and open sources, with nearly half of the incidents involving DDoS attacks, which overwhelm systems with excessive traffic. Both reports emphasize that software vulnerabilities are a major entry point for attackers. Microsoft notes that the time between when a vulnerability is discovered and when it is exploited has dropped below 24 hours. ENISA reports that 60.4% of unauthorized system accesses involved exploiting these weaknesses. In 2025, 48,000 new software vulnerabilities were identified, a 22% increase from the previous year. Both reports warn about the growing threat of supply chain attacks, where attackers compromise trusted software or services to gain access to other systems. ENISA mentions the increasing number of compromised npm packages, which are used to distribute software in the open-source community. One example is the Shai-Hulud campaign, which targeted these packages. Microsoft points to the Axios package, a widely used tool with over 100 million weekly downloads, which was compromised in March 2026. Open-source supply chain risks are now considered among the top threats for the coming year. ENISA identifies France as the second most cited country in the EU for ransomware claims in 2025, following Germany. Microsoft ranks France 17th globally and sixth in Europe for the impact of cyberattacks on its customers in the first half of 2026. Both reports suggest that AI is being used to improve existing attack methods rather than create entirely new ones. ENISA highlights an AI-assisted cloud intrusion that gained administrative access in just eight minutes. Microsoft notes that AI is being used in various stages of attacks, including gathering intelligence and manipulating people through social engineering. The reports warn that attackers currently have an advantage over defenders in using these advanced techniques. The European Commission has responded with an action plan focused on cybersecurity and AI, based on laws such as the AI Act and the Cyber Resilience Act. ENISA has also issued recommendations for managing risks from advanced AI models. Microsoft predicts that the most sophisticated AI-based attack techniques will become common within a year, with new categories of threats emerging. ENISA anticipates that AI could take over more steps in the attack process, potentially allowing attacks to occur without human involvement.