
Microsoft identified government agencies and public services as the main targets of attacks and proposed five priorities to strengthen security resilience.
AI-generated summary
Microsoft released its annual "Digital Defense Report" to analyze global cyber threat trends from July 2025 to June 2026. The report pointed out that government agencies have become the main target of national-level operations because they possess sensitive information.
The degree of cyber security threats faced by Taiwan ranks among the top in the world. Microsoft's latest annual "Microsoft Digital Defense Report" recently released pointed out that in the first half of 2026, Taiwan ranked 4th in the world and 1st in the Asia-Pacific among the countries and regions most frequently affected by information security threats; in the sample of country/region-level activities in the Asia-Pacific region, Microsoft also observed 193 incidents related to Taiwan.
This year's report compiles and analyzes the cyber threat trends observed between July 2025 and June 2026. From a global perspective, government agencies and public services are not only the areas most severely affected by information security threats, but are also the most frequently targeted targets of nation-state actions.
Microsoft pointed out that the government holds sensitive information, provides services necessary for people's livelihood, and is at the core of the networks of various agencies, contractors, technology service providers, and critical infrastructure operators, making it an attractive target for attacks.
In the face of the rapid evolution of cyber threats, Microsoft believes that security in the AI era is no longer just about preventing individual intrusions, but more importantly, ensuring that government agencies can still operate effectively in an environment where risks are interconnected, attacks change rapidly, and attackers can even remain hidden for a long time. In addition, the importance of public-private sector cooperation has also increased, not only involving the protection of critical government infrastructure, but also the policies and regulations required to respond to emerging technologies.
Regarding how the government can strengthen the resilience of information security, Microsoft further proposed five major priorities:
The first is to prepare for a more rapidly changing threat environment. Microsoft pointed out that AI is compressing the response time of information security. The time required for an attacker to discover a vulnerability and actually use it in an attack may be far less than 24 hours. At the same time, the number of publicly disclosed software vulnerabilities (usually identified and tracked by CVE numbers) is expected to hit a record in 2026, reaching 72,000.
Therefore, the government should develop the ability to quickly collect and evaluate information, make decisions, and coordinate and cooperate across agencies and industries. It should also clearly define responsibilities and establish trustworthy cooperative relationships before an incident occurs.
The second is to integrate security into the AI ecosystem. As governments continue to introduce AI into public services, Microsoft believes that AI security should be viewed as a resilience challenge rather than a purely technical issue. Since AI systems involve infrastructure, data, models, applications, suppliers and governance processes, the government should implement the "secure-by-design" principle, strengthen testing and evaluation, supply chain resilience and transparency, implement accountability mechanisms and deepen international cooperation.
The third is to plan in advance the response mechanism for the spread of information security incidents. When governments face information security intrusions, it is often difficult to immediately determine whether they are cybercrimes, geopolitical or other threats. Microsoft pointed out that although cybercriminals and country-level actors have different goals, they are increasingly using the same intrusion vectors, including identity theft, exposed applications, social engineering and normal IT management tools.
In addition, Microsoft found that 52.2% of intrusions involving valid accounts ultimately led to the theft of other credentials, showing that attackers can quickly expand their operations from an initial foothold, and what may originally appear to be an independent incident may further evolve into ransomware, espionage, data theft, or disruption of critical services. Therefore, contingency planning should also take suppliers, partners and service providers into consideration.
The fourth is to promote real-time and two-way information sharing between the public and private sectors. Microsoft pointed out that the occurrence of account theft in a single organization may be an early warning of larger-scale attacks. Therefore, information sharing cannot only be one-way reporting by enterprises to the government. Government agencies should also provide actionable information, guidance and warnings to help organizations protect their own networks, customers and operations.
The fifth is to ensure that key services can continue to operate when encountering emergencies. Microsoft pointed out that transportation systems, communications infrastructure, schools, universities and critical infrastructure operators are increasingly becoming targets of cyberattacks. Therefore, the government should not only understand its own system to build security resilience, but also understand the overall ecosystem that supports the operation of public services.
Microsoft recommends that the government should regularly conduct "tabletop exercises" to invite policymakers, operational decision-makers, law enforcement agencies, critical infrastructure operators, and private enterprise partners to jointly simulate response methods when critical services are interrupted, and to identify deficiencies in decision-making, information sharing, external communication, and cross-departmental coordination before a real crisis occurs.
Microsoft believes that as cyber incidents begin to span organizations and countries, security resilience no longer depends only on technical readiness, but also on the ability of various organizations to collaborate effectively under pressure. As AI-driven and cyber threats continue to become more interconnected, resilience is not just about recovering from attacks, but the ability to control damage, adjust quickly, and continue to provide critical services when people need them most.

Microsoft AI Economic Research Institute released the "Global AI Usage Report" for the second quarter of 2026, showing that 31 economies around the world have AI penetration rates exceeding 30%. Taiwan ranks 19th in the world with a penetration rate of 33.8%, ahead of China's 17.5%, and the penetration rate continues to grow.

The "Continuity and Transformation of Artificial Intelligence Governance Research" academic seminar and the annual meeting of the Digital Communication Ethics Committee of the China Science and Technology Journalism Society (2026) were recently held at Communication University of China. Experts and scholars conducted in-depth discussions and exchanges around the theory, policy, global ethics and interdisciplinary issues of artificial intelligence governance.

US intellectual property firm MIPS is collaborating with Chinese companies to advance the open-source RISC-V chip architecture, maintaining cross-border cooperation despite ongoing geopolitical tech rivalry between Washington and Beijing.

LINE is expected to launch the "Premium Blocking" function in the fall of 2026. After blocking the other party, paying members can delete their account from the other party's friend list. This feature aims to provide a more radical digital fade-out, sparking a polarizing discussion about the handling of relationships in Japan.

Microsoft released the "Digital Defense Report", pointing out that in 2026, government agencies will be subject to information security threats, accounting for 27%, ranking first among all industries in the world. The report emphasizes that attackers gain access through phishing and account theft, and the system latency is extended, resulting in a significant increase in the risk of ransomware and data theft.

Hong Kong's first pure electric ferry "Coral Sea No. 88" was officially put into service on October 3, with routes between Kwun Tong and Sai Wan Ho. The ship is powered by lithium iron phosphate batteries and solar panels to achieve zero emissions and incorporates elements of Hong Kong's industrial history and culture, aiming to enhance citizens' travel experience and support the development of Hong Kong's cultural tourism.