Why this month's Microsoft patch release is a doozy

Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.

Why this month's Microsoft patch release is a doozy

TL;DR

  • Microsoft's September patch fixed a record-breaking 972 vulnerabilities, 112 of which are critical.
  • This is part of an industry-wide trend of record vulnerability disclosures, spurred by AI-assisted discovery.
  • Companies are increasing bug fixes in anticipation of AI-enabled cyberattacks.
  • Notable vulnerabilities include zero-days in Windows, Exchange Server, Microsoft Authenticator, SharePoint, SQL Server, and Remote Desktop Services.
  • Many identified vulnerabilities are 'wormable,' meaning they can spread autonomously across networks.
  • The effectiveness and cost of AI in finding vulnerabilities are debated, but results show a significant increase in bug discovery.