August 5, 2026

Microsoft's AI Is Writing Security Patches Now

Microsoft's AI Is Writing Security Patches Now

570 fixes in one Patch Tuesday. Let that sink in.

Microsoft recently patched around 570 vulnerabilities in a single Patch Tuesday cycle, and the tool behind much of that work is an internal AI system called MDASH. That's not a typo. Five hundred and seventy holes, many of them found by AI before attackers could find them first. If you run Windows machines in your office, that number affects you directly.

For small and mid-size businesses in NJ and NYC, the practical implication is simple: the volume of patches you need to apply is going up, not down. AI is surfacing vulnerabilities faster than any human security team could. That's mostly good news, but it means your patching process has to keep pace. A backlog of uninstalled updates is a real exposure.

What Microsoft is actually building

According to reporting from Neowin, Microsoft is working on a product called Project Perception. It's designed to scan code for security vulnerabilities using AI, and it will pull from models built by Microsoft, OpenAI, and Anthropic. The goal is to compete with Anthropic's Mythos model, which does similar work but is apparently expensive to run. Microsoft wants the same capability at a lower cost, using a model router that assigns the right AI to each task.

Project Perception is expected to launch this month. It's being led by Hayete Gallot, Microsoft's head of security, who took the role in February and has been reorganizing the security division around AI products. Whether MDASH and Project Perception are the same thing or related isn't confirmed yet, but the direction is clear: Microsoft is betting heavily on AI to find bugs before the bad guys do.

Access will likely be restricted at launch, similar to how Anthropic has handled Mythos and Fable. These tools can find exploitable flaws in software before patches exist, which makes them genuinely dangerous in the wrong hands.

Why this changes your patching math

Here's the thing most business owners miss. When Microsoft patches 570 vulnerabilities at once, that's not just a big number to scroll past. Each unpatched machine in your fleet is potentially exposed to some subset of those flaws until the update lands and installs successfully. AI is accelerating both sides of this, defenders find bugs faster, but so do attackers once details become public.

I've written before about how AI is finding more bugs and why your patches can't wait, and this news reinforces that point. The gap between "patch released" and "exploit in the wild" keeps shrinking. Waiting a week or two to test updates before deploying them is reasonable. Waiting a month is not.

If you're managing Windows updates manually, or relying on individual employees to approve restarts, you're going to fall behind. Tools like Windows Update for Business, Intune, or a managed patching service exist precisely because humans are bad at this at scale.

What you should actually do

The basics still apply, and they matter more now, not less.

For more context on what a large-scale patch cycle looks like in practice, the breakdown of those 570 Windows vulnerabilities and what NJ businesses should do is worth reading.

The trend is only going one direction. AI-assisted vulnerability research means more patches, more often. Your process needs to match that reality. If you want help building one that does, booking an IT assessment is a good place to start.

FAQ

Did Microsoft really patch 570 vulnerabilities at once?

Yes. Microsoft patched around 570 vulnerabilities in a recent Patch Tuesday cycle, using an internal AI tool called MDASH. That's an unusually large number and reflects how AI is accelerating the pace at which vulnerabilities are found and addressed.

What is Microsoft Project Perception?

Project Perception is a Microsoft security tool in development that uses AI to find vulnerabilities in software code. It combines models from Microsoft, OpenAI, and Anthropic and is expected to launch this month. It's designed to compete with Anthropic's Mythos at a lower operating cost.

How often should a small business apply Windows updates?

Most businesses should target a two-week maximum window after a patch is released. Waiting longer increases exposure, especially as AI tools make it easier for attackers to identify and exploit newly disclosed vulnerabilities quickly after details become public.

Can AI replace a human IT team for security patching?

Not yet. AI tools like MDASH help find vulnerabilities faster, but someone still needs to test, schedule, and verify that patches deploy correctly across your specific environment. Automation helps, but oversight matters, especially when a bad update causes problems.

Tomasz Sobolewski, founder of Exine LLC
About the author
Tomasz Sobolewski
Founder of Exine LLC. Hands-on IT, cybersecurity and backup for growing New Jersey businesses, with 15+ years in the field. The kind of support that knows your systems and picks up the phone.