Microsoft's AI vulnerability detection results in record-breaking Patch Tuesday, addressing 974 security flaws
Both source and solution?
Microsoft's AI-powered vulnerability detection has led to a record-breaking Patch Tuesday, addressing 974 security flaws in both Windows 10 and Windows 11. This update is the largest Patch Tuesday to date, with 438 elevation of privilege vulnerabilities, 258 remote code execution vulnerabilities, and 19 security feature bypass vulnerabilities.
Two actively exploited zero-days, CVE-2026-85880 and CVE-2026-81963, were also targeted, both previously used to grant attackers elevated system privileges. Microsoft started using AI for vulnerability detection in July, focusing on high-confidence findings for fixing. The AI bug-hunting tools have received praise, with the CTO of Firefox highlighting how an early version of Claude Mythos found 271 security vulnerabilities in the browser.
Anthropic also boasted about its AI finding thousands of high-severity vulnerabilities. Recent AI-related security incidents, such as the wiki incident and Hugging Face incident, show mixed results for OpenAI's approach. Microsoft's Edge team has implemented an automated browser extension review system to manage the influx of AI-assisted submissions.
It remains to be seen if this automated system utilizes AI or machine-learning. The dual role of AI as both a source of security incidents and a tool for addressing vulnerabilities is an intriguing development in the world of cybersecurity.
Written by urgent.news from PC Gamer's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.