Microsoft Patches Record 570 Bugs After Letting AI Loose on Its Code
When tech giants boast about using artificial intelligence to write code, they forgot to mention that AI is also outstanding at finding the massive, terrifying pile of digital garbage they've been shipping us for decades.
The tech giant's security team deployed a custom AI scanning system called MDASH (Microsoft Security Multi-model Agent Scanning House) to automatically scour the source code of Windows and its sister products.
This digital bloodhound utilizes multiple large language models to hunt down security holes, essentially acting like a hyperactive intern who actually reads the terms of service.
These AI agents flag suspicious code blocks, run them through an automated verification pipeline to filter out false alarms, and then dump a mountain of confirmed issues onto the desks of exhausted human engineers. This automated dragnet is part of a broader industry shift, with the US CISA similarly using Anthropic's Fable model to dig up digital skeletons in government-issued software.
Of the massive batch of patches, 59 vulnerabilities were classified as critical, threatening to turn corporate networks into public playgrounds. The breakdown of fixed flaws includes 254 privilege escalation bugs, 145 remote code execution vulnerabilities, 102 leaks of confidential information, and dozens of other flaws causing system crashes or security bypasses.
This impressive catalog of digital negligence doesn't even count the 468 separate bugs inherited from Google's Chromium base for the Edge browser.
At the top of the urgency list are three zero-day vulnerabilities that became public knowledge before the patches dropped. Cybercriminals are already actively exploiting CVE-2026-56155 in Active Directory Federation Services to gain local admin privileges, alongside CVE-2026-56164, which allows hackers to remotely seize control of SharePoint servers via a single web request.
The third zero-day, CVE-2026-50661, allows bad actors to bypass BitLocker encryption entirely, though they need to physically touch the target computer to pull it off.
Unleashing AI to find bugs is a brilliant way to realize that the software powering the modern world is held together by digital duct tape and wishful thinking. Now that the floodgates are open, IT administrators globally are looking at a future of perpetual, sleepless weekends spent installing endless patches.
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.