Posts from this author will be added to your daily email digest and your homepage feed.
Engineers at Microsoft typically enjoy a quieter summer to take vacations and spend time with family, as is common at many companies. But this year, the season has been unusually busy for Windows and security engineers, thanks to new AI models that are discovering software vulnerabilities at a rapid pace. Sources tell me that Microsoft will set another patch Tuesday record today, the third in just a few months.
It all kicked off in April when Anthropic’s new Mythos model found security vulnerabilities in “every major operating system and web browser.” A few weeks later, OpenAI released its own cybersecurity-focused model to trusted partners. Sources familiar with Microsoft’s security work tell me both of these models have contributed to a record-breaking series of patch Tuesdays over the summer period.
Microsoft typically patches around 100 flaws every month, but in June it set a new record of around 200 fixes. July’s patch Tuesday was even bigger, with Microsoft patching at least 570 security holes, almost triple the number of June’s record-breaking release. Microsoft engineers had a chance to catch their breath a bit in August when they plugged nearly 400 security vulnerabilities.
I understand today’s September patch Tuesday is about to set a new record, with more than 650 security fixes for Windows alone. That’s six times the number that usually got patched before the AI models arrived. Engineers have been busy over the summer verifying fixes for hundreds of important patches, which include remote code vulnerabilities, privilege escalations, and more.
As Microsoft uses more and more security-focused AI models to discover software vulnerabilities, the number of flaws that need patching keeps increasing. While today’s patch Tuesday is another record-breaking event, I wouldn’t be surprised to see this record broken again — particularly if there’s another model advance soon.
Like many other software companies, Microsoft is urgently hunting for vulnerabilities before the advances in AI let malicious actors exploit undiscovered weaknesses in Windows, Azure, and other software. While Microsoft is issuing an unusual number of fixes, the sheer amount is also putting pressure on businesses that rely on Microsoft’s software to apply the patches as soon as possible.
IT admins typically have to test patches from Microsoft to ensure any fixes don’t interfere with critical business applications. This process can create what’s called a “patch gap” between a vulnerability being disclosed and people applying the fix. In an AI era of security vulnerabilities being rapidly discovered and disclosed, there’s a huge amount of pressure on businesses to close the patch gap.
Anthropic discovered earlier this year that Mythos could even create working exploits for newly disclosed software vulnerabilities in a matter of hours, instead of weeks. This puts businesses at risk of being hit by an exploit if they don’t patch soon enough. It’s particularly risky if Microsoft discovers remote code vulnerabilities that are easy for hackers to exploit.
The patch gap has always been a risk in cybersecurity, but with the sheer volume of vulnerabilities being discovered in the AI era, I’m sure we’ll see Microsoft and others warning companies once again to apply patches as soon as they’re released. When hundreds of vulnerabilities are now being discovered every month, time is very much of the essence.
... continue reading