// Blog / News

AI is driving record Patch Tuesdays

Share

On August 11, Microsoft released another enormous batch of security fixes: more than 400 vulnerabilities in a single month, including one already being exploited in the wild. A year ago a Patch Tuesday this size would have been shocking. Now it is close to routine, and Microsoft has been unusually candid about why: it has pointed its own artificial intelligence at its code, and AI is finding flaws faster than ever. That shift changes what "staying patched" asks of a small business.

This month's patches

August's release covered more than 400 flaws, 42 of them rated critical, and three zero-days (bugs known before a fix existed). One was already under active attack: CVE-2026-68820, a flaw in a core Windows networking component (the WinSock driver, afd.sys) that lets an attacker who is already on a machine elevate their access to full SYSTEM control. Check Point tied the exploitation to Lazarus, a North Korean state-linked group, which used it to plant a stealthy kernel rootkit. Two other zero-days were publicly disclosed but not yet seen in attacks. The practical instruction is the usual one, only more urgent: apply this month's Windows updates promptly.

Why the numbers keep climbing

The bigger story is the trend line. June set a record of around 200 fixes, July shattered it with roughly 570, and August landed north of 400. Microsoft attributes the surge to an AI-powered vulnerability-discovery system it now runs against the Windows codebase around the clock, hunting for exploitable flaws before attackers do. In its own words, it warned that Patch Tuesdays would keep growing as AI-assisted bug-finding scales up. Both Microsoft's engineers and the wider security community, and attackers too, are increasingly using AI to find bugs. Heavy Patch Tuesdays are the new normal, not a spike.

The double-edged part

On balance this is good: bugs Microsoft's AI finds and fixes are bugs an attacker cannot use. But the same techniques cut both ways. Attackers use AI to hunt for flaws and to reverse-engineer patches the moment they ship, working out what was fixed so they can attack anyone who has not updated yet. So the window between "patch released" and "patch exploited" is shrinking, exactly as the number of patches to keep up with is exploding. Falling behind is riskier than it used to be.

What it means for a small business

No small team can hand-track hundreds of CVEs a month, and you do not need to. What you need is a process that keeps the important updates flowing without someone babysitting it:

  • Turn on automatic updates for Windows and your main software, so routine patches land without anyone remembering to click.
  • Prioritize by real risk, not raw count. The ones that are actively exploited or rated critical are what matter this month; the rest can follow on a normal cycle.
  • Do not forget the edges: third-party apps, browsers, plugins, and device firmware are patched separately and are where many attacks actually land.
  • Make someone accountable. "Patching happens automatically, and someone confirms it did" beats assuming it did. This is the kind of quiet, ongoing work a managed approach exists to handle.

Sources:BleepingComputerSecurityWeek

Not sure whether your Windows machines, apps, and firmware are actually staying patched? We set up and run patch management for small businesses, so the important updates land on time and someone is accountable for confirming it.

Talk to us

Related