Lead story
622 Patches in One Day: Microsoft's AI Vulnerability Machine Is Running Hot
Last month, Microsoft's June Patch Tuesday dropped around 206 CVEs and everyone called it unprecedented. Yesterday, the company more than tripled that figure — shipping fixes for 622 vulnerabilities in a single release. Two of them were already being actively exploited before the patches landed.
The two zero-days are the ones defenders should move on first. One sits in Active Directory, the other in SharePoint Server. Microsoft says incident responders flagged both, which means attackers had already found them in the wild and were using them before any fix existed. A third flaw — in BitLocker — was publicly disclosed before yesterday's release, giving potential attackers a head start there too.
The sheer volume of this release is the real story. Microsoft has been open about the reason: the company is now using AI to systematically scan its own codebase for vulnerabilities, and the machine is finding them faster than any human team could. The June record of ~206 was itself a spike; 622 in a single month represents an exponential jump. CyberScoop quoted Microsoft warning customers that a flood was coming. It delivered.
This raises a genuinely uncomfortable question. If AI is surfacing vulnerabilities at this rate, the backlog inside large software estates — not just Microsoft's — may be far larger than the industry previously assumed. Every patch that ships is a good thing. But the remediation burden on enterprise security teams is growing faster than most patching programmes can absorb.
The practical advice for defenders is straightforward, even if the workload is not: prioritise the two actively exploited zero-days (Active Directory and SharePoint), then the publicly disclosed BitLocker flaw, then tier the rest by exposure. The CVSS scores and Microsoft's own exploitability ratings are your triage guide. Anything internet-facing or handling authentication comes first.
For Australian organisations, this is a significant patch cycle. Active Directory and SharePoint are deeply embedded in Commonwealth and state government environments, as well as enterprise Australia broadly. The Australian Signals Directorate's Essential Eight maturity framework includes patching as a core control — but at 622 CVEs, even organisations sitting at Maturity Level 3 will need to think carefully about prioritisation workflows. The ASD's ACSC advisory feed is worth watching for any follow-on guidance specific to Australian critical infrastructure sectors.
The bigger pattern is worth stepping back to consider. We are entering an era where AI doesn't just help attackers move faster — it also helps defenders (and vendors) find flaws faster. The question is whether the defensive side of that equation scales quickly enough. Right now, the answer is: not obviously. Security teams are already stretched. A tripling of patch volume in a single month is a stress test most weren't ready for.
Watch for whether other major vendors — Google, Oracle, Adobe — follow with similarly inflated patch counts as they adopt comparable AI scanning. If this is an industry-wide shift, yesterday's "patchpocalypse" may become the new normal.
