Microsoft's July patch batch hits 570 flaws as AI speeds bug discovery
Microsoft's July Patch Tuesday addressed at least 570 security flaws, almost triple the count from the previous month. The company attributed the surge to AI-aided vulnerability discovery; EVP Pavan Davuluri wrote in a July 9 post that users should expect higher volumes of security updates because of AI. Nearly 60 of the bugs carry a critical rating, and three are zero-days, two already exploited in the wild.
The fixes include roughly 250 elevation-of-privilege flaws, among them bugs in Active Directory Federation Services and SharePoint. A BitLocker bypass requiring physical access was publicly detailed but is not known to be exploited, while a remote code execution flaw in Microsoft Copilot scored 9.6 on the CVSS scale. One SharePoint zero-day, originally rated unlikely to be exploited, was added to CISA's Known Exploited Vulnerabilities list on July 1 — a reminder that severity estimates can miss.
The systems everyone depends on for work, communication, and services rest on this software. A record patch load is a setback for the reliability of that shared infrastructure: more flaws to fix means more windows for attackers and more urgency on defenders. AI cuts both ways here — the same tooling finding bugs for vendors can find them for attackers.
The broader trend is worth watching: Adobe moved to twice-monthly bulletins citing AI, Google's June batches topped 900 fixes, and researchers reported an Anthropic model generating proof-of-concept exploits for 13 of 14 flaws rated unlikely to be exploited. Those red-team findings and exploitability ratings are assessments, not settled facts.
Source: Krebs on Security
MANY MINDED