344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps175
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support132
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
Microsoft released its September security updates, fixing about 972 software flaws, including 112 rated critical, as the industry braces for AI-assisted attacks.
In short: Microsoft’s September updates fix about 972 security flaws, including 112 rated “critical,” which is a new monthly record.
Microsoft released an unusually large set of security updates for September. Security researchers counted about 972 vulnerabilities fixed, and 112 of them were rated critical. “Vulnerabilities” are weaknesses in software that can let attackers break in, like a faulty lock on a door.
The count is not perfectly exact because Microsoft updates can include fixes that were handled earlier or that affect related software. A researcher at the Zero Day Initiative put the total at 972, or 997 if you also count fixes brought over from Chromium, the browser code that Microsoft Edge is built on.
Some of the flaws are especially worrying because they could be used with little or no user action. The researcher said he saw more than 20 “wormable” issues. That means an attack could spread from one computer to another on its own (like a contagious illness moving through a crowd).
Microsoft also patched two “zero-days,” meaning flaws that were not publicly known before the fix and may have been used by attackers. There is no public information on who used them or how widely. Other examples mentioned include serious issues affecting Exchange Server, SharePoint, Remote Desktop, and SQL Server.
Several security teams say the industry is entering a “new normal” where companies ship far more fixes because AI tools are helping find bugs faster. The key question is whether real-world attacks will rise to match, and whether people and organizations can install these updates quickly enough.
Source: Arstechnica