
Today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month. Microsoft Plugs Nearly 1,000 Security Holes.
This monthโs patch bundle obliterates the software giantโs previous record set in July, when it released updates for at least 570 security vulnerabilities. Septemberโs Patch Tuesday brings this yearโs total to more than 2,600, more than twice Microsoftโs previous record-setting patch year in 2020 (1,245) and with three more months to go. There are two โzero-dayโ flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on Windows system.
Fully 113 of the bugs addressed today earned Microsoftโs โcriticalโ rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user. Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns that an unauthenticated attacker could uses this weakness simply by sending a specially crafted packet to an affected system, and that it is likely to be exploited.
Weโre sharing an AI-generated solution to the NavierโStokes Millennium Prize Problem, including a writeup and a formal proof in Lean. On the NavierโStokes Millennium Prize Problem.
Artificial intelligence has solved a major mathematics problem, but credit for the accomplishment is murky. What’s going on with OpenAI and the Navier-Stokes controversy.
Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks. Why this month’s Microsoft patch release is a doozy.
It’s a major accomplishment, but the news has been marred by a debate over whether the company acted based on unpublished research from other parties. OpenAI has been accused of attempting to influence who will receive credit for the achievement in publication.
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Microsoftโs patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It was only two months ago that Microsoft patched a then-record 570 vulnerabilities.
The Navier-Stokes problem First, some background. The Millennium Prize Problems are a group of seven complex questions established by the Clay Mathematics Institute in 2000.
Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months.
The organization is offering a reward of $1 million for solutions to each of these questions, all of which have stymied mathematicians for decades, if not centuries. Since the prize’s creation, only one of the other problems from the collection had previously been solved.
Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an open letter warning of a narrowing window for patching vulnerabilities ahead of an expected tsunami of AI-enabled attacks that actively exploit them first. The industry is taking the threat seriously by pumping out record-setting numbers of patches in their software.
Welcome to the new normal Dustin Childs, a researcher at the Zero Day Initiative, calls the spikes the โnew normalโ and also cautions that despite them, the damage thatโs likely to result from AI-assisted attacks could eventually be substantial. โOn the one hand, congrats to the security gnomes at Microsoft for being able to patch bugs at this rate,โ Childs wrote Tuesday.
Discover more from ChuckysCarnage
Subscribe to get the latest posts sent to your email.
