Patch Apocalypse Continues Unabated as Vulnerabilities Multiply
The Patch Apocalypse continues to intensify, with record numbers of patches being released and reported CVEs continuing to grow. August's Patch Tuesday was the second biggest in history, with 398 resolved CVEs - 42 rated Critical, 355 rated Important, and 1 rated Moderate. However, despite the high number of patches, only one vulnerability was confirmed actively exploited in the wild, and two more were publicly disclosed ahead of the released patches.
The use of AI has been instrumental in discovering vulnerabilities, but so far, there has been a slow response from threat actors to exploit these discoveries. Microsoft's Corporate Vice President for Azure Networking, Igor Sahknov, suggests using network controls as a way to mitigate threats and reduce risk during the patching process.
A key challenge facing organizations is the sheer volume of patches and the time it takes to test and deploy them. According to Sahknov, 'The objective is not to avoid patching. The objective is to create a meaningful layer of defense during the period when patching has not yet been completed.'