Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery

Microsoft on Tuesday launched fixes for 419 safety vulnerabilities, one of many largest month-to-month counts on report and the newest signal that synthetic intelligence is dramatically growing the variety of software program flaws safety groups should take care of.

In Could, when Microsoft shipped patches for 137 vulnerabilities, the corporate said the trade had reached a second “the place AI-powered vulnerability discovery stops being speculative and begins being an engineering downside.”

Since then, successive record-breaking releases — 206 in June, adopted by 622 in July — have seen the corporate explode previous its annual report for vulnerabilities, of round 1,250.

In accordance with the corporate’s August release notes, the newest replace addresses 62 vital and 357 important-rated points. As with final month, Microsoft not lists the person CVEs and has changed the beforehand itemized batch with a abstract desk exhibiting a depend of bugs by product household, alongside a “Notable CVEs” part.

This month’s replace options about 5 instances the quantity of patches Microsoft was delivery in a typical month earlier than AI-assisted vulnerability discovery took maintain. On the eve of that surge, Britain’s Nationwide Cyber Safety Centre warned that organizations wanted to arrange for a brand new tempo in mitigating vulnerabilities.

Three of this month’s flaws are zero-days. Two had been publicly disclosed earlier than the patches dropped, whereas considered one of which — CVE-2026-68820, affecting the Home windows element that handles community connections — has been seen exploited within the wild.

The corporate tied the assaults to a marketing campaign by Lazarus Group, which has been been concentrating on candidates for “engaging job alternatives at well-known corporations within the protection, aerospace, and aviation industries” in an advanced assault that sees them mix PDFs with a trojanised reader permitting the hackers to secretly take management of the candidates’ machines.

One of many publicly-known flaws, CVE-2026-62832, was attributed by Microsoft to an nameless researcher. The main points of the vulnerability seem to match a proof-of-concept referred to as LegacyHive revealed by the pseudonymous researcher Nightmare Eclipse hours after final month’s Patch Tuesday — the newest instalment in a months-long standoff over the corporate’s disclosure and bounty practices.

Widespread exploitation of the surge in vulnerabilities has not but been noticed. However the 5 Eyes intelligence alliance warned in June that frontier AI fashions would quickly be “essentially reworking each offensive and defensive cyber capabilities,” including “the timeline just isn’t years, it’s months.”

The discharge date marks the beginning of an everyday cycle for cybersecurity defenders. As soon as a patch is out, attackers choose it aside in an try and reverse-engineer the holes it plugs after which race to interrupt into machines that haven’t but been up to date — a phenomenon usually described as “Exploit Wednesday.”

Though the quantity of bugs seemingly makes it harder for Microsoft to supply an in depth advisory, the brand new clustered format of the Safety Updates web page dangers making triage extra advanced. Defenders and third-party trackers should now piece collectively the total image from underlying advisory feeds themselves and work out what must be patched first.

Get extra insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *