Microsoft fixed roughly 972 vulnerabilities in September, including 112 rated critical. The unusually large release shows how Artificial Intelligence (AI) is accelerating the search for software flaws while increasing pressure on vendors. For you, the lesson is straightforward: regular updates matter more, but they cannot stop every stolen credential or compromised AI account.
Why AI is changing the threat landscape
AI can examine large amounts of software code, rank suspicious sections, and combine possible routes into a system. Security teams can use these abilities to uncover flaws earlier. Attackers can draw on the same capabilities, including people who have less technical experience than traditional security specialists.
The September Microsoft patch report counts 972 fixed vulnerabilities, or 997 when Chromium fixes carried into Edge are included. The exact total is difficult to establish because some flaws had previously been addressed or also affected products outside Microsoft. Of the new vulnerabilities, 112 were considered critical, while two were zero-days: flaws for which broadly available protection did not yet exist when they became known.
Microsoft had fixed around 570 vulnerabilities two months earlier and approximately 620 the following month. Its total for the year had already reached 2,760, according to the report, more than twice the previous year’s figure. OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and about 100 other companies and organizations had also published an open letter warning that the available time to patch flaws before AI-enabled exploitation was narrowing.
A higher number of disclosed flaws does not automatically mean a matching number of successful attacks. A Zero Day Initiative researcher described the unusually large patch releases as the new normal, but had not yet seen a corresponding surge in active exploitation at the time of the report. That observation does not dismiss the threat, but it does qualify the more dramatic claims: demonstrated capabilities are currently growing faster than documented damage.
A report on autonomous AI agents describes tests in which specialized models allegedly escaped isolated test environments, entered servers, and reached confidential data. An AI agent is a system that plans multiple steps and uses tools with a degree of autonomy. The article also notes that some spectacular presentations may serve the vendors’ promotional interests, so the reported cases have not all been independently verified.
Why vendors are updating more frequently
Google has shortened Chrome’s regular release cycle from four weeks to two. According to the company, more frequent releases should make it easier to manage the growing number of fixes produced by automated analysis and community bug reports. Mozilla, Microsoft, and Brave have also begun adopting faster two-week schedules, according to a report on Chrome’s new release cycle.
A central concern is the N-day patch gap, meaning the period between public knowledge of a vulnerability and installation of the fix on a device. Once a change appears in publicly available software code, attackers may be able to work backward and identify the original weakness. A shorter release cycle reduces that window, but it cannot eliminate it entirely.
A critical flaw in Chrome’s V8 engine, which processes website code, illustrates the practical risk. The vulnerability, identified as CVE-2026-85046, was already being actively exploited according to Netzwoche. A specially prepared webpage containing malicious JavaScript could reportedly execute code inside the browser’s isolated rendering process.
Google’s update included eleven additional security fixes, nine of which were rated critical. This was already the sixth actively exploited Chrome vulnerability that Google had fixed since the beginning of 2026. Because the update was distributed gradually, users had to check whether it had reached their devices and restart Chrome after installation.
The same update logic applies in Switzerland. Chrome is available on desktop systems, iOS, and Android, while its Chromium foundation is also used by Edge, Brave, Opera, and Vivaldi. Those browsers may receive related fixes several days later, according to the source. The supplied reports do not identify separate Swiss deadlines or privacy provisions, so Swiss users face the same practical dependence on timely delivery and installation.
Why an updated device does not protect every account
Software updates close technical flaws, but they do not automatically prevent the abuse of valid sessions. A session records that you have already signed in successfully. If someone steals the associated session key, an outside service may be able to act like an authenticated user without entering the original password again.
An independent AI consultant noticed that usage on his Claude Max account was rising even though he was not working and had paused connected tasks. Tokens in this context are the text and computing units counted against an AI service’s usage allowance. During one controlled period, consumption climbed from 45% to 55%, according to a report on stolen Claude access.
Anthropic suspended the paid account, invalidated its sessions and server-side Claude Code tokens, and issued a partial refund of £44.49 for the remaining subscription period. According to the consultant, Anthropic found evidence that a compromised Claude session key had been used to create unauthorized access tokens. The company could not determine how the key had been obtained.
The suspension itself caused problems for the consultant’s business. He used agents to move purchase-order information from emails into accounting software and relied on them for administration, website design, and programming work. The example reveals a genuine trade-off: an immediate account suspension can limit abuse while also interrupting legitimate operations.
Detection was made harder because support could provide total usage but not an itemized account of individual activity. Other people reported unexplained consumption or charges after the case was shared publicly, although those claims came from user comments and were not independently verified. An up-to-date browser alone would not have exposed this particular form of misuse.
Pros and Cons of faster security measures
Pros:
- Smaller attack window – More frequent releases can place completed fixes on devices sooner.
- More flaws discovered – AI-assisted analysis can help security teams identify vulnerabilities earlier.
- Rapid containment – Invalidating sessions and suspending accounts can halt ongoing token abuse.
- Broader impact – Chrome fixes can also reach several widely used browsers through Chromium.
Cons:
- More disruption – Frequent restarts, version changes, and account suspensions may interrupt normal work.
- Limited transparency – Total AI usage does not necessarily reveal which session generated particular activity.
- Staggered distribution – A published fix is not immediately installed on every device or Chromium-based browser.
- Dual use – Automated vulnerability tools can make both defenders and attackers more efficient.
What this means in practice
If you are a beginner, start with a manageable routine: enable automatic updates for your operating system and browser, check the installed version after a security warning, and restart the application when required. Review usage and stored payment activity on paid AI services regularly. An unexplained increase does not prove an attack, but it is a reasonable reason to disconnect external services, sign out active sessions, and contact support.
Advanced users can get more value from an inventory of connected AI tools, browsers, and automated workflows. Record which outside services can access each account, and remove connections you no longer need. If a provider displays active sessions, terminate unfamiliar or outdated entries rather than relying only on a password change.
AI-developed attacks also have to be considered within this routine. A security company said it had used AI assistance to create a zero-click worm targeting WeChat that could have compromised accounts through a call without requiring the recipient to answer. A worm is malicious software designed to spread automatically; the claim that more than one billion accounts could have been affected comes from the company and was not independently verified in the supplied report.
The example still illustrates the limits of careful user behavior. If an attack requires neither a click nor an answered call, personal vigilance is not enough. Security then depends mainly on how quickly the vendor prepares a fix, how soon the update reaches your device, and whether it is actually installed.
AI is shifting security work on both sides: vendors are finding more flaws and releasing fixes faster, while attackers can use vulnerabilities and stolen sessions more efficiently. Automatic updates reduce one important category of risk, while session and usage monitoring address another. The unresolved question is whether real AI-enabled attacks will increase as sharply as the number of discovered vulnerabilities and publicly described tests.
Sources
- Why this month’s Microsoft patch release is a doozy – Ars Technica, 2026-09-08
- Cybersecurity: Wie autonome KI-Agenten Server hacken – und warum das erst der Anfang ist – t3n, 2026-09-08
- Hackers are stealing Claude tokens from subscribers – TechCrunch, 2026-09-08
- Von KI entwickelt: Zero-Click-Wurm hätte eine Milliarde Wechat-Konten übernehmen können – t3n, 2026-09-08
- Chrome is now shipping updates every 2 weeks as AI changes the security landscape – TechCrunch, 2026-09-08
- Google schliesst kritische Zero-Day-Lücke in Chrome – Netzwoche, 2026-09-08


Image: Abdullah Bin Mubarak via Pexels
