AI's impact is being felt across the enterprise, but the challenges it brings are perhaps most pertinent for security teams charged with patching a growing list of vulnerabilities discovered by AI bug hunters. For the first time, patching quickly may be more important than patching cautiously, one cyber VP recently told The Stack.

Security researchers have been warning that an increasing load of vulnerabilities has been coming for years, but in recent months the issue has kicked up a notch. Microsoft released a record 620 patches in its July Patch Tuesday release, seemingly prompted by the arrival of Anthropic’s zero day hunting Mythos model.

While Microsoft's 421-strong August security update release Tuesday shows vulnerability growth may not be as exponential as some feared, there's no doubt the number of vulnerabilities is spiking after Oracle set an industry record by patching 1449 CVEs in one day last month.

Recent releases from OpenAI have also increased the stakes, especially after the Hugging Face hacking incident in which two OpenAI models found a zero-day vulnerability in a cache proxy and reached the open internet.

In mid-July, Microsoft’s Windows EVP Pavan Davuluri warned customers to expect “a higher volume of security updates” going forward, and the US government launched, amid heavy scepticism, its “Gold Eagle” initiative to deal with the issue as an “AI cybersecurity clearinghouse.”

“We absolutely need security operations teams to be able to operate at a faster pace," SANS Institute Instructor Andy Smith, who is also the head of security architecture at software firm Sage, told The Stack. "Otherwise, they're just going to be drowned out by an increasing amount of even low-level attacks.”

“There's no way to stay successful if you're going to rely on the legacy processes,” said Ivan Milenkovic, vice president of cyber risk technology for Qualys. “For the very first time, I think the risk of not patching outweighs the risk of a patch bringing down a production service.”

Old practices and legacy infrastructure

Get the full story: Subscribe for free

Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.

Subscribe now

Already a member? Sign in