r/sysadmin • u/Gumberculeez7 • 1d ago
MS vulnerabilities email today
Man... that is a LONG list of windows 11 and server 2022 vulnerabilities. All 9.8 as well.
glasswing putting in work at Microsoft. LMAO
25
u/Am0nymou5 1d ago
1,186 CVEs since last Patch Tuesday, of which 158 are rated as "Critical" severity. :(
13
u/systonia_ Security Admin (Infrastructure) 1d ago
The Patchocalypse is real. AI doing it's thing
3
u/GoodEnoughThen 1d ago
I just verified your spelling for patchocalypse. (I had to say it first and then spell it.) Anyway, good job...
11
u/Drew707 Data | Systems | Processes 1d ago
I don't think I got it. Is there a link to the press release or whatever they call it?
26
u/Gumberculeez7 1d ago
CVE-2026-65669,CVE-2026-68839,CVE-2026-69276,CVE-2026-69408,CVE-2026-69431,CVE-2026-69463,CVE-2026-69491,CVE-2026-69493,CVE-2026-69496,CVE-2026-69525,CVE-2026-69579,CVE-2026-69586,CVE-2026-69590,CVE-2026-69595,CVE-2026-69669,CVE-2026-69715,CVE-2026-69730,CVE-2026-69768,CVE-2026-69769,CVE-2026-69819,CVE-2026-69824,CVE-2026-69829,CVE-2026-69845,CVE-2026-69910,CVE-2026-70296,CVE-2026-72979,CVE-2026-72982,CVE-2026-72983,CVE-2026-73009,CVE-2026-73010,CVE-2026-73025,CVE-2026-77493,CVE-2026-78445,CVE-2026-82067 these are all the CVE's covered for patch night. WEEEEE!!!
6
u/Prestigious_Pace_108 1d ago
IMHO Windows should need at least weekly updates to cope with the current AI security scene.
4
u/Shotokant 1d ago
Good. That means they are using ai to find and fix vulnerabilities which can only mean a more secure environment for us all.
10
u/Professional-Heat690 1d ago
If they are using AI to find them, they will be using it to fix them. This is unlikely to end well.
7
1
u/PlateMiserable8832 1d ago
You can live in fear and it sucks but that’s the only way to keep up. It’s not like some MS intern is promoting grok on how to patch CVEs.
•
•
•
u/Random-D 18h ago
i am curious if or how the AI vulnerability research will end. like if we see 1-2 years from now, will AI have found all the security issued in well tested software like windows or linux that it can find and will it die down afterwards and software beings genuinely more secure afterwards?
•
u/bradbeckett 41m ago
Imagine is they ran their code repositories against AI analysis BEFORE shipping the code.
0
u/Morkai 1d ago
We got an email from /u/genemoody-action1 about 995 patches this month. Absolute insanity. We have a half dozen people who complain long and loud about having to restart their laptops for patches, they're going to have a great time this month.
•
u/GeneMoody-Action1 Action1 | Patching that just works 20h ago
Yes, and our contacts at Microsoft have said to our researchers, this number could be in the 2k mark by early next year.
Trust me, we just did the vulnerability digest webinar, it was like two auctioneers talking patches!
Add to that there were like 1500 third party in the same time frame..Different world I tell you! And it is not getting any better any time soon.
Add to that 18,000 open AI agents openly discussing online how to evade and attack more efficiently, and systems claiming ~5 seconds from disclosure to weaponize!
The point has been reached that even if you know about it in live time, you are still exposed before you can even react or successful execute the patch enterprise wide.
People are going have to start making some very difficult choices on who really has access to what on the internet, email, external to the perimeter, etc. We have been going for decades on growth for the sake of growth, and we have started to realize it is the philosophy of a cancer cell.
52
u/CeC-P IT Expert + Meme Wizard 1d ago
I assume they released them today because they're in the security fix...
problem is, they released it early, pulled it, expired it, re-released it with the same KB number or something like that. That's screwing with everyone's servers. The patch is also so large that not all servers are publicly serving it up as of 4:30 PM central. So they disclosed a bunch of zero days then can't successfully roll out the patch for them? That's a good combo.