Why Are There Suddenly so Many Fixes in Microsoft’s Patch Tuesday Updates?

If you’re a Windows user, hopefully you’ve installed Microsoft’s regular “Patch Tuesday” updates, which fix critical security vulnerabilities in the company’s software. The patches over the past few months have been particularly important, as they included a record number of bugs and numerous zero-day vulnerabilities that were actively exploited or publicly disclosed.
This week’s Patch Tuesday patch release in August was no exception: the update patched 400 vulnerabilities, including three zero-day vulnerabilities. Compare this to March, when Microsoft released patches for only 83 bugs (two of which were publicly disclosed as zero-day vulnerabilities). The sudden increase in the number of vulnerabilities and security patches is largely due to artificial intelligence.
Artificial intelligence creates vulnerabilities (and detects them).
In the security space, AI plays a dual role. Attackers use AI to develop and deploy hacking tools faster and more widely, potentially making vulnerabilities more vulnerable than before. This also forces tech companies to respond more quickly. As ZDNET notes , companies that patch vulnerabilities during regular update cycles (such as Patch Tuesday) are now forced to patch bugs more quickly and may begin shortening the intervals between updates, as Apple did this summer.
Artificial intelligence not only helps exploit vulnerabilities but also finds them so they can be patched. Last month, Microsoft announced that AI enabled its engineering teams to find and analyze more potential vulnerabilities before they are exploited. (The company noted that this also directly contributes to the increased number of security updates included in Patch Tuesday.) Google also uses AI to detect, triage, and patch security vulnerabilities in Chrome. It’s worth noting that while AI is good at identifying vulnerabilities, it is much less effective at actually fixing them —and can introduce more errors in the process.
As always, update your Windows device as soon as possible.
Windows users should install security updates as soon as they become available to minimize the risk of active exploits. Patch Tuesday updates are released around 10:00 AM on the second Tuesday of the month, and you should receive them automatically. However, you can check their status in the Start menu > Settings > Windows Update > Check for Windows updates.
As reported by BleepingComputer , the August security update addresses vulnerabilities in the following categories: 176 privilege escalation vulnerabilities, 11 security feature bypass vulnerabilities, 110 remote code execution vulnerabilities, 86 information disclosure vulnerabilities, 21 address spoofing vulnerabilities, and 12 denial of service vulnerabilities. Forty-two of these vulnerabilities are rated “critical” and include remote code execution and privilege escalation vulnerabilities.