• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
AimactGrow
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing
No Result
View All Result
AimactGrow
No Result
View All Result

Microsoft Patches a Document 570 Safety Flaws – Krebs on Safety

Admin by Admin
July 14, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Microsoft Corp. immediately launched software program updates to plug not less than 570 safety holes in its Home windows working programs and different software program, virtually triple the variety of vulnerabilities the software program large mounted in its record-smashing Patch Tuesday launch final month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by synthetic intelligence.

A picture of a windows laptop in its updating stage, saying do not turn off the computer.

Practically 60 of the bugs quashed in July’s Patch Tuesday earned a “crucial” severity ranking, that means miscreants or malware may use them to grab distant management over a Home windows system with little or no assist from the person. Microsoft additionally addressed three zero-day flaws which are already being exploited within the wild.

Two of the zero-day weaknesses enable an attacker to raise their person rights on a Home windows system, as do roughly 250 different elevation of privilege flaws mounted this month; they embody CVE-2026-56155 — an Lively Listing Federation Companies bug — and CVE-2026-56164, a Microsoft Sharepoint vulnerability.

CVE-2026-50661 is a safety characteristic bypass in Home windows BitLocker that would enable attackers to realize entry to encrypted information if they’ve bodily entry to the system. Microsoft stated this bug has been detailed publicly, however that it’s not conscious of any energetic exploitation.

In a weblog put up on July 9, Microsoft Govt Vice President Pavan Davuluri wrote that Home windows customers will discover “a better quantity of safety updates included in every safety launch” on account of AI aiding within the discovery of vulnerabilities.

“The tempo of vulnerability discovery is altering with advances in AI making it attainable to seek out extra points, sooner, throughout extra code, with new mechanisms that may speed up each discovery and evaluation,” Davuluri wrote.

Jack Bicer, director of vulnerability analysis at Action1, known as consideration to CVE-2026-48561, a distant code execution flaw in Microsoft Copilot (with a 9.6 CVSS risk rating) that permits an unauthorized attacker to execute code over the community. Microsoft says an attacker may exploit this bug by internet hosting a malicious web site that causes Microsoft Edge for Android to robotically ship crafted prompts to Copilot when a person visits the location.

As AI advances the state of vulnerability discovery and remediation, it is usually making it simpler for attackers to shortly devise working exploits for identified software program flaws. Microsoft has lengthy labeled safety bugs utilizing its “exploitability index,” which is Redmond’s greatest guess as to how seemingly it’s that attackers will have the ability to determine a dependable method to exploit a given vulnerability.

However Satnam Narang, senior workers analysis engineer at Tenable, argues that Microsoft’s exploitability index must do a greater job of shifting with the machine pace of discovery. For instance, Microsoft initially gave this month’s SharePoint zero-day an exploitability ranking of “much less seemingly,” though the flaw was added to CISA’s Identified Exploited Vulnerabilities listing on July 1.

“Anthropic’s Crimson Staff’s personal findings for identified vulnerabilities (n-days) revealed how fragile this method has turn out to be, with its Mythos Preview mannequin having the ability to produce proof-of-concept exploits for 13 of 14 vulnerabilities that had been rated ‘Exploitation Much less Probably’ or ‘Exploitation Unlikely,’” Narang stated. “What this implies is that our approach of Patch Tuesday has modified, as a result of the exploitability index is centered round people, not AI instruments, and as these instruments proceed to enhance, protection wants to enhance alongside it.”

Chris Goettl at Ivanti noticed that the report patch numbers from Microsoft come as quite a few different main software program makers are growing their patch cadence, together with Adobe which introduced immediately it’s shifting to twice-monthly safety bulletins printed on the 2nd and 4th Tuesday of every month (Adobe additionally cited AI for accelerating their patch cycles). Cisco, Mozilla and Oracle are also transport updates extra steadily, whereas Google’s patch batches in June 2026 totaled greater than 900 safety fixes, Goettl famous.

Backing up your Home windows system and/or information is all the time a good suggestion earlier than making use of working system updates. Given the amount of patches addressed this month it might be sensible for finish customers to attend a couple of days earlier than making use of these fixes. It’s not unusual for safety patches to introduce system stability points, and people probabilities most likely improve fairly a bit with the big patch depend launched immediately.

Additional studying:

Action1’s Patch Tuesday weblog

Automox’s rundown

Tags: FlawsKrebsMicrosoftPatchesRecordSecurity
Admin

Admin

Next Post
DC’s new Batman film lastly fixes Christopher Nolan’s largest Darkish Knight mistake

DC’s new Batman film lastly fixes Christopher Nolan's largest Darkish Knight mistake

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Establish content material made with Google’s AI instruments

Determine content material made with Google’s AI instruments

April 8, 2026
Gemma Scope 2: Serving to the AI Security Group Deepen Understanding of Complicated Language Mannequin Conduct

Gemma Scope 2: Serving to the AI Security Group Deepen Understanding of Complicated Language Mannequin Conduct

December 20, 2025

Trending.

Telegram ban in India sparks a rush to VPNs, rival apps

Telegram ban in India sparks a rush to VPNs, rival apps

June 19, 2026
The Full Information to EcoGPT

The Full Information to EcoGPT

June 6, 2026
12 Various Search Engines to Strive (As a substitute of Google)

12 Various Search Engines to Strive (As a substitute of Google)

January 30, 2026
High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

High LLM Observability and Analysis Platforms in 2026: Langfuse, LangSmith, Braintrust, Arize, and Extra In contrast

August 9, 2026
Greatest Swap 2 video games for vacation 2025

Greatest Swap 2 video games for vacation 2025

December 3, 2025

AimactGrow

Welcome to AimactGrow, your ultimate source for all things technology! Our mission is to provide insightful, up-to-date content on the latest advancements in technology, coding, gaming, digital marketing, SEO, cybersecurity, and artificial intelligence (AI).

Categories

  • AI
  • Coding
  • Cybersecurity
  • Digital marketing
  • Gaming
  • SEO
  • Technology

Recent News

The Pokémon Firm Appears to Sensible Gadget Integrations as Future Targets

The Pokémon Firm Appears to Sensible Gadget Integrations as Future Targets

August 29, 2026
Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

Attackers Exploit MCP RCE, Blind Immediate Injection and Reminiscence Credential Theft Towards AI Infrastructure

August 29, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Technology
  • AI
  • SEO
  • Coding
  • Gaming
  • Cybersecurity
  • Digital marketing

© 2025 https://blog.aimactgrow.com/ - All Rights Reserved