AI News Feed
Market watch
Cybersecurity

Microsoft Breaks Another Patch Tuesday Record

Microsoft's September Patch Tuesday brings a record 650+ Windows fixes, driven by AI vulnerability discovery.

The surge began in April, when Anthropic's Mythos model found security vulnerabilities in every major operating system and Web browser. A few weeks later, OpenAI released its own cybersecurity-focused model to trusted partners. Sources familiar with Microsoft's security work said both models contributed to the record-breaking series of Patch Tuesdays over the summer.

Microsoft typically updates about 100 flaws every month. In June, it fixed about 200. July's Patch Tuesday was larger, with at least 570 security holes patched. In August, the volume eased to nearly 400. Now, September is expected to surpass July with more than 650 fixes for Windows alone — about six times the volume Microsoft typically handled before the AI models arrived.

Engineers have spent the summer verifying fixes for hundreds of high-priority patches, addressing remote code execution vulnerabilities, privilege escalations, and other security issues. As Microsoft relies more on security-focused AI to discover flaws, the number of vulnerabilities requiring patches has kept climbing.

Like other software makers, Microsoft is pushing to find and close vulnerabilities before malicious actors use advances in AI to exploit them. But the higher volume of fixes is also creating new pressure on enterprises that depend on Microsoft's software. IT administrators typically need to test patches for compatibility with critical business applications, a process that can create a “patch gap” between disclosure and deployment. With vulnerabilities now being disclosed at a much faster pace, the window for closing that gap is shrinking.

Anthropic found earlier this year that its Mythos model could generate working exploits for newly disclosed vulnerabilities in hours, not weeks. That raises the stakes for companies that delay patching, especially when the flaws include remotely exploitable code execution bugs. The patch gap has long been a risk in cybersecurity, but the scale of AI-driven discovery in recent months has made prompt patching more urgent than ever.