SUMMARYMicrosoft released September security updates that fix about 972 vulnerabilities, including 112 rated critical, setting a new company record after a previous high of 570 two months earlier. Google and other firms have also disclosed unusually large numbers of bugs recently, and OpenAI, Anthropic, AWS, Google, Microsoft, and many others signed an open letter warning that AI-enabled attacks could outpace patching efforts.

Why this months Microsoft patch release is a doozy
Getty Images
arstechnica.com

Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.

It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out unprecedented numbers of patches in their software.

Welcome to the new normal

Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes the “new normal” and also cautions that despite them, the damage that’s likely to result from AI-assisted attacks could eventually be substantial.

Read full article