Microsoft’s Patching
Microsoft released a record number of security patches – approximately 972 – addressing a significant number of high-severity vulnerabilities. This surge in patching is driven by advancements in AI-powered vulnerability detection, leading to a heightened risk of AI-enabled attacks exploiting these newly discovered weaknesses. The industry is responding with an unprecedented volume of updates, but the threat landscape is evolving rapidly.
Microsoft released a substantial security update, marking a new record for the company. This update addressed a remarkable 972 vulnerabilities, with 112 classified as high severity.
This increase in patching activity is largely due to the growing use of AI in vulnerability discovery. Previously, Microsoft had set a record of 570 patches two months prior, and last month saw 620 vulnerabilities addressed. The industry as a whole is experiencing a similar trend, with Google and other companies reporting record vulnerability counts.
The rise in vulnerability numbers is a direct result of AI tools now being used to proactively identify weaknesses in software. The letter published two weeks ago by OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 other companies highlighted a growing concern: a rapidly shrinking window of opportunity to patch vulnerabilities before a wave of AI-powered attacks could exploit them.
AI is not only finding vulnerabilities but also adept at reverse-engineering existing patches to create exploits, further accelerating the risk. The industry is responding with an unprecedented volume of updates, but the long-term trend and the ultimate impact remain uncertain.