Skip to content

Microsoft Calls for a Rethink in Cyber Defense: Reactive Patching Is No Longer Enough

Bottom line: Microsoft is now processing and patching nine times as many vulnerabilities as it did in March, as AI tools radically accelerate vulnerability discovery and exploit development.

At Black Hat USA, David Weston, Group Manager on Microsoft’s Windows team, challenged classic best practices for vulnerability remediation. AI tools are making the discovery of security flaws and the development of exploits so cheap and fast that reactive patching is reaching its limits as a defense strategy.

In his keynote “The End of Rare: Defending When Offense Is Cheap,” Weston explained that today’s best practices for vulnerability remediation date back to an era when developing exploits was time-consuming and costly. That assumption no longer holds. As evidence, he cited figures from the Microsoft Security Response Center (MSRC): the number of vulnerabilities processed and patched there is currently doubling every six weeks. Compared to March, Microsoft is now handling nine times the vulnerability volume seen back then. Weston attributes this acceleration to the growing use of more capable AI tools and stresses that this is not a Windows-specific problem but an industry-wide one — comparable correlations can also be observed on Linux and other operating systems.

A concrete example is MDASH (Multi-model Agentic Scanning Harness), an internal Microsoft tool that identified around 200 vulnerabilities in the Linux kernel of the internal Azure Linux distribution; Microsoft says it is working with the community to fix them. A new module in MDASH can automatically generate proof-of-concept exploit code from static analysis results. According to Weston, out of the 200 vulnerabilities found, 182 crash-level PoCs could be generated automatically, many of them fully functional exploits, some with root access. The average compute cost for discovery and exploit generation was $3.61, with a generation time of 21 minutes. Weston expects automated exploit generation to become a common, commercially available capability by the end of the year.

For defense, Weston says this means that traditional protection mechanisms are losing their effectiveness. Non-deterministic mitigations such as ASLR (Address Space Layout Randomization) remain a hurdle for attackers, but are unlikely to be sufficient in the medium term given AI-driven vulnerability discovery. Classic threat detection, which relies on the assumption that switching tools and techniques is costly and time-consuming for attackers, is also losing its foundation: whereas the repeated use of the same packers, obfuscation tools, and TTPs (Tactics, Techniques, Procedures) once gave detection patterns stability, autonomous operations now allow attackers to generate custom tools and frameworks tailored to each target instead of laboriously retraining operators.

For CISOs, the talk provides a rationale for shifting budgets and priorities away from pure patch speed and toward inherently resilient system architectures. Detection strategies that rely on attacker inertia and tool reuse should be reviewed, as these assumptions are increasingly being undermined by AI-driven, autonomous attack operations.


Source: www.csoonline.com · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: