By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Microsoft Patches Record 972 Vulnerabilities in September

Microsoft released its September security update, addressing a record-breaking 972 vulnerabilities, with 112 of these classified as critical severity. This marks a significant increase in the volume of patched vulnerabilities compared to previous months. In July, Microsoft had previously patched a then-record 570 vulnerabilities, followed by approximately 620 vulnerabilities in August. This trend of escalating vulnerability disclosures and patching efforts is not isolated to Microsoft, as other major technology companies, including Google, have also reported record numbers of vulnerabilities in recent months. The heightened activity reflects a growing concern within the cybersecurity industry regarding the potential impact of artificial intelligence on cyberattacks.
Two weeks prior to Microsoft's September patch release, a joint open letter was published by a coalition of prominent technology organizations, including OpenAI, Anthropic, Amazon Web Services, Google, and Microsoft, alongside approximately 100 other companies and organizations. This letter issued a stark warning about a "narrowing window" for patching vulnerabilities. The signatories expressed apprehension about an anticipated "tsunami of AI-enabled attacks" that are expected to exploit these weaknesses proactively. The unprecedented number of patches being issued by software vendors underscores the industry's serious commitment to addressing this escalating threat landscape.
Dustin Childs, a researcher at the Zero Day Initiative, has characterized these spikes in vulnerability patching as the "new normal." While acknowledging the industry's proactive response in releasing a high volume of patches, Childs also cautioned that the potential damage resulting from AI-assisted cyberattacks could still be substantial. The increasing sophistication and speed at which AI can be leveraged to identify and exploit software flaws necessitate a continuous and robust patching strategy. The proactive patching of such a large number of vulnerabilities by Microsoft in its September update is a direct response to this evolving threat, aiming to mitigate risks before they can be exploited by malicious actors. The sheer scale of the September patch indicates the complexity and breadth of security issues being addressed, highlighting the ongoing challenge of maintaining secure software in the face of advanced cyber threats. The collaboration among leading tech companies in issuing the open letter further emphasizes the collective recognition of the significant and imminent risks posed by AI-driven cyber warfare, pushing the industry towards a more vigilant and rapid response to security vulnerabilities.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.