Microsoft Plugs Nearly 1,000 Security Holes
today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.
today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go. Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user.
Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment?
Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.” Satnam Narang is senior staff research engineer at Tenable .
What changed
Many other large software companies, including Adobe, Cisco, Google, Mozilla and Oracle, all have recently credited AI-assisted research with increasing their patch cadence and volume (Google said today it is now going to ship security updates every two weeks).
Narang said it’s important to recognize that while the number of vulnerabilities being patched by Microsoft is rising, the number of flaws that can and will affect most organizations remains quite low.
Who is affected
Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.” Satnam Narang is senior staff research engineer at Tenable .
Why this matters
Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment?
How organizations are responding
Microsoft is hardly alone in shipping monster patch bundles lately.
What to watch next
Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.
Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.
What remains unknown
The available reporting does not establish who is behind the activity, if an attacker is involved.