Why this month's Microsoft patch release is a doozy
Key Points:
- Microsoft’s September patch fixes a record 972 vulnerabilities, including 112 critical-severity ones, surpassing previous monthly records of 570 and 620 vulnerabilities patched in recent months.
- The surge in vulnerabilities patched is part of a broader industry trend, with companies like Google and OpenAI warning of an impending wave of AI-enabled attacks exploiting software flaws.
- Notable vulnerabilities include two zero-days in Windows services, a remote code execution flaw in Exchange Server triggered by a malicious email attachment, and multiple privilege escalation bugs in Microsoft Authenticator and SQL Server.
- Many vulnerabilities patched are wormable, meaning they can spread without user interaction, raising concerns about potential rapid exploitation and chain reactions across systems.
- While AI-assisted vulnerability discovery is controversial due to costs and false positives, early results show it is uncovering unprecedented numbers of severe bugs, signaling a new phase in cybersecurity efforts.