Microsoft’s record-breaking Patch Tuesday is a vulnerability itself

Microsoft has rolled out the biggest Patch Tuesday ever, including a staggering 570 vulnerabilities. 58 are rated critical, 509 important and, of critical importance (every pun intended), two zero-days are already being exploited in the wild by threat actors.

Now, you may think this is something of a “meh” situation. Same patching problem, just bigger. And you would be right, to a point. The simplistic approach to burgeoning vulnerability counts is to suggest that it’s still a patching job, and size doesn’t matter.

But, as always, the devil is in the detail.

Google now issues weekly security updates for Chrome, and in June also broke its record with 429 confirmed security vulnerabilities. Adobe has switched to bi-monthly security releases. So, do you stick to your monthly patch management schedule or move to weekly/bi-monthly for some companies? If the latter, that’s more stress on security teams.

What about testing before rollout? How do you prioritise? Jon Levenson, a director at Automox, told me that “active exploitation outranks a bigger number,” when it comes to severity ratings, which is good advice.

He adds that “the size of this release is the headline, but the response is the same one that’s worked for 20 years”. That’s where I’m not sure I can agree.

Managing patch management

Microsoft has confirmed it’s using “agentic scanning” to identify vulnerabilities faster, which is why security teams are seeing ever increasing update numbers.

“What we’re observing,” said Mayuresh Dani, Security Research Manager at Qualys Threat Research Unit, “is that AI-automated fuzzing, LLM-assisted variant hunting, and static analysis at scale are discovering bugs faster than enterprises can remediate.”

And that, in my never humble opinion, isn’t business as usual.

Dani recommends that enterprises should move from CVSS-only prioritisation to something more aligned to the CISA Known Exploited Vulnerabilities catalog – or even a ‘Likely Exploited Vulnerabilities’ model – and graduate to a tiered patching SLA mechanism.

For example, KEV-listed could be tier one remediation, high-privilege infrastructure such as VPN gateways and remote admin consoles in tier two, and so on.

Josh Picolet, SVP of Threat Detections at Team Cymru, told me that the problem is the clock starts before the advisory is published. “Patching is essential, but it only closes the vulnerability,” he said. “It does not reveal whether an attacker has already staged infrastructure, established persistence, or begun targeting your environment.”

The game has changed, and the goal isn’t merely to patch more quickly; it’s to know about the threat sooner.

“The organisations best positioned to respond are those that have robust detection capabilities that can see beyond their own perimeter into the command-and-control, hosting, and staging infrastructure supporting the campaign,” Picolet warned.

His conclusion: “The earlier defenders can detect the infrastructure behind an attack, the more time they have to act, which can be the difference between a contained threat and a material event.”

More security articles by Davey Winder

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.