Microsoft Patches a Record 570 Security Flaws

Microsoft has just released software updates to plug an astonishing 570 security holes in its Windows operating systems and other software. This is nearly triple the number of vulnerabilities fixed in last month’s record-breaking Patch Tuesday release. The sheer scale of these patches raises concerns about the evolving threat landscape, where artificial intelligence (AI) is increasingly being used by both attackers and defenders.

The majority of these bugs are elevation-of-privilege flaws, which could allow an attacker to take control of a Windows device with little or no user interaction. Microsoft has addressed three zero-day vulnerabilities that have already been exploited in the wild. Two of these zero-day weaknesses enable an attacker to elevate their privileges on a Windows system, while another allows an attacker to bypass security features and access encrypted data if they have physical access to the device.

The use of AI in vulnerability discovery is being credited for the surge in patch numbers. Microsoft’s Executive Vice President Pavan Davuluri recently stated that users will notice “a higher volume of security updates included in each security release” due to AI-powered discovery mechanisms. However, this shift also means that attackers can quickly devise working exploits for known software flaws.

Satnam Narang, senior staff research engineer at Tenable, argues that Microsoft’s exploitability index needs to adapt faster to the changing landscape. The index currently assesses how likely it is for an attacker to develop a reliable exploit, but AI has made this process much quicker and more efficient. As a result, vulnerabilities rated as “less likely” or “unlikely” are being quickly exploited by attackers.

The record patch numbers from Microsoft come at a time when other major software makers are also increasing their patch cadence. Adobe, for example, is moving to twice-monthly security bulletins, while Cisco, Mozilla, and Oracle are shipping updates more frequently. Google’s patch batches in June totaled over 900 security fixes.

For end users, it’s essential to exercise caution when applying these patches. Given the volume of changes, it may be wise to wait a few days before updating your system. Patches can sometimes introduce stability issues, and the chances of this happening increase with such a large patch count. As always, backing up your data is crucial before applying operating system updates.

Ultimately, the rapid evolution of AI-powered vulnerability discovery and exploitation underscores the need for continuous improvement in cybersecurity practices. As attackers adapt to these changes, defenders must also evolve their strategies to stay ahead of the threats.


Source: Krebs on Security — 2026-07-14