Why Microsoft Patch Tuesday Updates Suddenly Have So Many More Fixes
Microsoft is addressing more critical security vulnerabilities than ever, and there's a reason for it.
If you're a Windows user, you've hopefully installed regular Patch Tuesday updates from Microsoft, which address critical security vulnerabilities across the company's software. The last few months' worth of fixes have been especially important, as they've included a record number of bugs and a swath of zero-days that have been actively exploited or publicly disclosed.
The August Patch Tuesday release this week is no different: The update fixes 400 flaws, including three zero-days. Compare that to March, when Microsoft issued patches for just 83 bugs in total (two of which were publicly disclosed zero-days). The seemingly sudden uptick in vulnerabilities and security fixes is due, in large part, to AI.
AI is creating vulnerabilities (and discovering them)
AI is playing both sides of the field when it comes to security. Threat actors are using AI to develop and deploy hacking tools more quickly and at scale, so more flaws may be more exploitable than before. This forces tech companies to respond more quickly as well. As ZDNET notes, companies that patch vulnerabilities during regular update cycles (like Patch Tuesday) now have to rush to address bugs sooner and may begin to shorten the time between updates, as Apple did earlier this summer.
While AI is helping to exploit vulnerabilities, it is also finding them so they can be fixed. Last month, Microsoft announced that AI has allowed its engineering teams to find and analyze a larger volume of potential flaws before they can be exploited. (The company noted that this also directly contributes to the increase in security updates included in Patch Tuesday). Google, too, is using AI to discover, triage, and fix security flaws in Chrome. It's worth noting that while AI is good at identifying vulnerabilities, it is far less effective at actually patching them—and may introduce more bugs along the way.
As always, update your Windows device ASAP
Windows users should ensure security updates are installed as soon as they're available to minimize the risk of active exploits. Patch Tuesday is released around 10 a.m. on the second Tuesday of the month, and you should receive them automatically. However, you can check the status under Start > Settings > Windows Update > Check for Windows updates.
As BleepingComputer reports, the August security update addresses flaws across the following categories: 176 elevation-of-privilege vulnerabilities, 11 security feature bypass vulnerabilities, 110 remote-code-execution vulnerabilities, 86 information disclosure vulnerabilities, 21 spoofing vulnerabilities, and 12 denial-of-service vulnerabilities. Forty-two of the bugs are rated "critical" and include remote code execution and elevation of privilege flaws.