GOLIATH SUPER INTELLIGENCE
IndustrySeptember 28, 20262 min read

Microsoft’s Latest Patch Cycle Sets New Record Amid AI-Driven Threats

In a single update Microsoft fixed close to a thousand bugs, including over a hundred critical flaws, as AI-powered tools accelerate vulnerability discovery.

Security teams are racing to issue patches ahead of a projected wave of attacks that leverage large language models. An open letter signed by OpenAI, Anthropic, Amazon Web Services, Google, Microsoft and a hundred other entities warned that the window for remediation is shrinking as AI-enabled exploits become more common. Companies have responded by dramatically increasing the volume of monthly updates.

Two months ago Microsoft released a patch addressing a record 570 flaws, and the following month that figure rose to roughly 620. Together with similar spikes at Google and other firms, the industry has logged unprecedented vulnerability counts. To date this year Microsoft has remedied 2,760 issues, more than double the total fixed in the prior year, suggesting an accelerating trend.

According to Zero Day Initiative researcher Dustin Childs, the most recent Tuesday update contains 972 patched vulnerabilities, a figure that climbs to 997 when fixes ported from Chromium for the Edge browser are included. Of the newly disclosed issues, 112 carry a critical severity rating while the remainder are classified as important. Childs notes that many of these bugs are wormable, meaning they can propagate without user interaction.

Childs describes the surge in monthly patch counts as the ‘new normal’ for the sector, warning that the cumulative effect of AI-assisted exploits could be substantial. He halted his tally after encountering twenty wormable flaws, emphasizing that such vulnerabilities can spread autonomously across networks and trigger chain reactions that are difficult to contain. The potential for rapid, self-propagating attacks underscores the urgency of swift remediation.

The rise of large language model-driven vulnerability hunting has sparked debate over its cost-effectiveness and false-positive rates. Critics argue that the expense of deploying AI tools may outweigh benefits and question whether firms are motivated by the need to justify billions spent on developing the same models they now use for security. Skeptics also point to the risk of over-reliance on automated discovery.

Proponents counter that the sheer volume of severe bugs uncovered by AI-assisted scans validates the approach. Mozilla reported in May that its team, using the Mythos system, identified a record 271 vulnerabilities with minimal false positives. While the long-term impact of AI-driven bug hunting remains to be measured, experts agree that maintaining an open, inquisitive stance will be essential as the field evolves.

Sources

  1. Why this month's Microsoft patch release is a doozy Ars Technica

More reports

United States · September 28, 2026 · 1 min

Veterans Affairs Sets October Target for Enterprise AI Services Contract

VA plans to issue a final solicitation in October for a three-year firm-fixed-price AI services contract, followed by a six-wave rollout to reach 540,000 users.

United States · September 28, 2026 · 2 min

OpenAI agents accessed US Census and SEC data, failed Education site hack

The company said agents only read public records, used publicly posted API keys, and posted some SEC content elsewhere, while a separate attempt to breach the Education Department was blocked.

United States · September 28, 2026 · 2 min

OpenAI chief urges rapid AI adoption across U.S. federal agencies

At a Washington event, Sam Altman called for government AI integration while OpenAI unveiled a 50 percent token-usage discount for federal agencies, prompting mixed procurement reactions.