Skip to content

Microsoft calls for a rethink in cyber defense: reactive patching is no longer enough

Bottom line: Microsoft is now processing and patching nine times as many vulnerabilities as in March, as AI tools radically accelerate vulnerability discovery and exploit development.

At Black Hat USA, David Weston, Group Manager on Microsoft’s Windows team, challenged classic best practices for vulnerability remediation. AI tools make finding security vulnerabilities and developing exploits so cheap and fast that reactive patching is reaching its limits as a defense strategy.

In his keynote “The End of Rare: Defending When Offense Is Cheap,” Weston explained that today’s vulnerability remediation best practices originated in an era when developing exploits was time-consuming and costly. That assumption no longer holds. As evidence, he cited figures from the Microsoft Security Response Center (MSRC): the number of vulnerabilities processed and patched there is currently doubling every six weeks. Compared to March, the volume of vulnerabilities handled has now increased ninefold. Weston attributes this acceleration to the growing use of more powerful AI tools and emphasizes that this is not a Windows-specific issue but a cross-industry problem — comparable correlations can also be observed with Linux and other operating systems.

A concrete example is MDASH (Multi-model Agentic Scanning Harness), an internal Microsoft tool that identified around 200 vulnerabilities in the Linux kernel of the internal Azure Linux distribution; according to Microsoft, the company is working with the community to fix them. A new module in MDASH can automatically generate proof-of-concept exploit code from static analysis results. According to Weston, of the 200 vulnerabilities found, 182 crash-level PoCs could be generated automatically, many of them fully functional exploits, some with root access. The average compute cost for discovery and exploit generation was $3.61, with a generation time of 21 minutes. Weston expects automated exploit generation to become a common, commercially available capability by the end of the year.

For defense, Weston argues, this means that traditional protective mechanisms are losing effectiveness. Non-deterministic mitigations such as ASLR (Address Space Layout Randomization) remain a hurdle for attackers, but are unlikely to suffice in the medium term given AI-assisted vulnerability discovery. Classic threat detection, which is based on the assumption of high costs and time investment for attackers when switching tools and techniques, is also losing its footing: whereas the repeated use of the same packers, obfuscation tools, and TTPs (Tactics, Techniques, Procedures) once gave detection patterns stability, autonomous operations now allow attackers to generate tools and frameworks tailored to each target instead of having to retrain operators at great expense.

For CISOs, the talk provides a rationale for shifting budgets and priorities away from pure patch speed toward inherently resilient system architectures. Detection strategies that rely on attacker inertia and tool reuse should be reviewed, as these assumptions are increasingly being undermined by AI-driven, autonomous attack operations.


Source: www.csoonline.com · Published August 13, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: