Microsoft formalizes heavy use of AI for vulnerability discovery
Microsoft says generative AI is now part of its vulnerability management process, especially for Windows and other products.
NEXT (FR) — The company says LLMs help surface issues earlier, while human engineers still handle validation, risk decisions and final quality checks. Microsoft expects more security updates as a result.
Microsoft has explained how generative AI and large language models are now woven into its vulnerability management work. The goal is to shorten the gap between finding a flaw and protecting customers, with priority given to higher-risk areas.
AI is now brought in earlier in the development cycle, but humans still handle the assessment, the risk trade-offs and the final quality checks to make sure fixes meet the expected standards.
The change is already affecting update volume. After June’s Patch Tuesday set a record with nearly 200 flaws fixed, Microsoft says customers should expect more security updates in each release. The company stresses that this reflects better detection and handling of problems, not a decline in Windows security.
Readers’ Forum
No contributions yet — open the debate.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Waiting for your click …
·