Microsoft issued a massive security update addressing approximately 972 software vulnerabilities, including 112 critical-severity flaws and two zero-day exploits in Windows services. The update follows consecutive monthly records from Microsoft and comes alongside similar vulnerability spikes reported across Google and other major software vendors, bringing Microsoft’s year-to-date patched flaws to 2,760.
The surge in security patches highlights the growing impact of AI-assisted vulnerability discovery tools used by researchers and malicious actors. Security experts noted that over 20 patched vulnerabilities in the latest release were wormable, meaning they could propagate across networks automatically without user interaction.
The release follows an open letter signed by OpenAI, Anthropic, AWS, Google, Microsoft, and 100 industry partners warning of an imminent wave of AI-driven cyberattacks. While automated flaw hunting has increased patch velocity, critics remain divided over the cost, false-positive rates, and potential arms race created by defensive AI tools.
Why it matters
AI-assisted vulnerability discovery is accelerating patch cycles, forcing enterprise security teams to handle unprecedented update volumes.
The rising prevalence of AI-discovered wormable flaws heightens operational risks for enterprise infrastructure.
Big tech vendors are heavily prioritizing automated defensive AI to counter anticipated AI-driven cyberattack waves.
Source: arstechnica.com



