deniz.in

Markets

Weather

Loading weather

· via The Verge

AI vulnerability hunting drives Microsoft to a record 650-fix September Patch Tuesday

Microsoft shipped more than 650 Windows fixes in its third record Patch Tuesday in months, The Verge reports, as AI models from Anthropic and OpenAI uncover vulnerabilities far faster than before.

AI vulnerability hunting drives Microsoft to a record 650-fix September Patch Tuesday

Microsoft has set its third Patch Tuesday record in just a few months, with September's release carrying more than 650 security fixes for Windows alone, according to The Verge. The report attributes the unusually heavy workload to new AI models that are uncovering software vulnerabilities at a pace the company has never had to process before.

A summer of broken records

The Verge traces the streak back to April, when Anthropic's Mythos model identified security flaws in every major operating system and web browser. A few weeks later, OpenAI released a cybersecurity-focused model to a group of trusted partners. Sources familiar with Microsoft's security work told the outlet that both models fed directly into a run of record-setting patch releases over the summer.

The scale ramps up quickly. Microsoft historically ships around 100 fixes per month. June brought roughly 200, which was a record at the time. July nearly tripled that figure with at least 570 patched vulnerabilities. August saw a relative slowdown at just under 400, and September now tops the sequence with more than 650 fixes for Windows — roughly six times the volume that was typical before the AI models arrived, The Verge reports.

The patches cover serious categories, including remote code execution flaws and privilege escalation issues, and engineers spent much of the summer verifying fixes across hundreds of separate vulnerabilities.

AI on both sides of the equation

The surge is not simply about housekeeping. According to The Verge, Microsoft and other software vendors are racing to locate weaknesses in Windows, Azure and their other products before advances in AI hand comparable discovery capability to malicious actors.

That threat is not hypothetical. Anthropic found earlier this year that Mythos could build working exploits for newly disclosed vulnerabilities within hours rather than weeks, dramatically compressing the window between a flaw becoming public and it being weaponised. Remote code execution bugs that are easy to exploit are the most dangerous case, since a fast follow-on exploit could hit systems before administrators have acted.

The patch gap is the bottleneck

The practical strain now falls on the businesses that run Microsoft's software. IT teams normally test patches before deployment to make sure fixes do not break critical applications, which creates a lag — known as the patch gap — between a vulnerability being disclosed and the fix actually being applied.

With hundreds of vulnerabilities now being disclosed and patched every month, that gap becomes the main point of risk. The Verge notes that Microsoft and other vendors are likely to keep pressing customers to apply patches as quickly as possible after release, because the volume of discovery shows no sign of slowing. The outlet also expects the September record to fall again, particularly if another jump in model capability arrives.

Why it matters

This story is one of the clearest examples yet of AI reshaping the economics of software security. Vulnerability discovery has become cheap and fast, while verification, patching and enterprise deployment remain slow and human-paced. That asymmetry benefits whoever moves first — and right now defenders are moving fast, but attackers equipped with similar models could close the gap quickly. For any organisation running Windows at scale, the operational lesson is direct: monthly patch cycles that were sized for roughly 100 fixes now have to absorb several times that volume, and the safe window between disclosure and exploitation is shrinking from weeks to hours.

  • #microsoft
  • #security
  • #patch-tuesday
  • #artificial-intelligence
  • #windows
  • #vulnerabilities

Related posts