Microsoft’s 3-Day Patching Directive Comes with Added Operational Risk
Experts say AI is cutting patching time to hours as attackers can exploit flaws in nine hours and Microsoft issues more than 600 fixes.
- AI-Powered tools are accelerating the timeline for attacks, forcing companies to patch software flaws in hours rather than days as hackers weaponize vulnerabilities faster than defenders can respond.
- Even before AI-powered tools accelerated attacks, companies struggled to patch critical flaws; Verizon's annual report showed median patching times rose to 43 days last year, up from 32 days in 2024.
- Hido Cohen, cyber research lead at security firm Dream, observed attackers creating working exploits just nine hours after disclosure. "Nine hours is faster than most patch approval processes even convene," Cohen said.
- CISO Rich Baich and Hugh Thompson urged organizations to focus on preventing attacks and identity security, writing, "Our profession shouldn't be defined by how efficiently we observe compromise." Former CISA Director Jen Easterly noted the Known Exploited Vulnerabilities catalog requires updates.
- The Trump administration started accepting reports to its AI-powered vulnerabilities clearinghouse last week, as experts suggest the cybersecurity race will shift toward building tools that can prioritize and remediate flaws before attackers strike.
13 Articles
13 Articles
Oracle drops 1,449 security patches like it's the new normal
It's a bad day to be an Oracle admin: Big Red has just released 1,449 security patches ready to be applied. The patches were released as part of the company's quarterly security fixes, and the record number may partly reflect Oracle's internal push to harness AI for vulnerability detection, which it announced in April. Oracle also manages a huge product portfolio, and the patches span numerous products, so the total shouldn't come as too much of…
Microsoft’s 3-day patching directive comes with added operational risk
Microsoft 365 Director Jeremy Chapman this month took to video to tell Windows admins that the days of delaying security patches are over. Complex enterprise systems and historic incidents involving patch problems have caused many admins to hold fire on immediately applying security patches, in many cases deferring patch rollouts for two to four weeks or more to ensure stability. Microsoft argues that this cautious approach, though understandabl…
AI is shrinking the time to patch software vulnerabilities
Oracle patched more than 1,400 vulnerabilities through quarterly security updates.
Oracle Hospitality Simphony Multiple Vulnerabilities
Oracle’s July 2026 Critical Patch Update addresses four remotely exploitable vulnerabilities affecting Oracle Hospitality Simphony. Discovered and responsibly disclosed by Horizon3.ai researcher Jimi Sebree, the vulnerabilities affect two Simphony components: the EGateway Printing Handler and the Kiosk application. Together, they provide multiple paths for unauthenticated attackers to compromise… Source
Oracle’s July update fixes ten 10.0 vulnerabilities in Fusion Middleware
Oracle's July 2026 Critical Patch Update, its largest ever, contains 1,449 new security patches spanning 32 product families, from Oracle Database and E-Business Suite to PeopleSoft, GoldenGate, Java SE, and Fusion Middleware. Fusion Middleware was particularly hard hit, with new security patches for 355 security vulnerabilities, 219 of them remotely exploitable without authentication, meaning they can be exploited over a network without requiri…
Coverage Details
Bias Distribution
- 67% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




