Microsoft has released software updates to plug a staggering 570 security holes in its operating systems and other software, setting a new record for the company's Patch Tuesday release. The volume of fixes is nearly triple the number the software giant addressed in its previous record-breaking month. Microsoft attributed the burgeoning patch counts to advancements in artificial intelligence aiding in vulnerability discovery.
Nearly 60 of the bugs quashed in July's Patch Tuesday earned a "critical" severity rating, meaning attackers could use them to seize remote control over a Windows device with little user interaction. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild. Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, joining approximately 250 other elevation of privilege flaws fixed this month. The third zero-day is a security feature bypass that could allow attackers to gain access to encrypted data if they have physical access to the device.
The AI Effect
In a blog post, Microsoft Executive Vice President explained that Windows users will notice "a higher volume of security updates" as a result of AI aiding in the discovery of vulnerabilities. "The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis," he stated.
This AI-driven acceleration is forcing a shift in how security researchers approach Patch Tuesday. Microsoft has long used an "exploitability index" to label security bugs based on how likely it is that attackers will devise a working exploit. However, as AI tools become more powerful, they are able to quickly develop proof-of-concept exploits for flaws that were previously deemed "less likely." As a result, the index is becoming outdated, as researchers are now able to generate exploits for many of these previously dismissed vulnerabilities.
A Broader Trend
The record patch numbers from Microsoft are part of a broader trend. Adobe has announced it is moving to twice-monthly security bulletins, while Google's patch batches in June totaled more than 900 security fixes. As AI accelerates both the discovery of vulnerabilities and the creation of exploits, the window for defenders to patch their systems is shrinking. While these massive patch drops are a sign of improved detection, they also highlight the increasing complexity of securing modern software. End users are advised to wait a few days before applying these fixes, as the immense patch count increases the risk of system instability issues.