Skip to main content

Search complete. 140 mentions across 32 episodes found for "Patch".

Sep 11, 2026

Brad SamsHOST
1:21
Because that would be bad news bears if it did.
Brad SamsHOST
1:25
Microsoft shipped a record number of updates this week as part of Patch Tuesday.
Brad SamsHOST
1:33
964.
Brad SamsHOST
1:34
964.
Johannes UllrichHOST
1:39
Still, you probably don't want to do this.
Johannes UllrichHOST
1:43
And as it has become traditional following Microsoft's Patch Tuesday, we of course get Nightmare Eclipse's Zero Day Wednesday.
Johannes UllrichHOST
1:52
The latest vulnerability here is dubbed ShieldCrash, and it's actually not a fundamentally new vulnerability.
Johannes UllrichHOST
2:00
It's ShieldBreak, but, uh, it does expand this older vulnerability to bypass the fix, uh, that Microsoft has implemented for this.
James AzarHOST
18:21
So review your API access controls and usage logging there as well.
James AzarHOST
18:25
Yesterday, a few days ago, was Patch Tuesday.
James AzarHOST
18:29
And some patches didn't make it in time for us here on the show to talk about them.
James AzarHOST
18:32
One of those is the ICS Patch Tuesday.
James AzarHOST
18:34
So we know what water facilities are getting chased down by the Iranians.
James AzarHOST
18:41
So pay close attention to Schneider Electric's CVSS 9.2 Siemens S4 criticals and Rockwell RS links.
Sam BownePANELIST
36:17
Then they just patched it again, and he did it again.
Sam BownePANELIST
36:19
Nope, your patch is still crap.
Sam BownePANELIST
36:21
And I think each time he waited until just after Patch Tuesday to do that.
Sam BownePANELIST
36:25
Yes,
Paul AsadoorianHOST
36:26
yes,

41 MINS LATER

Paul AsadoorianHOST
77:09
And it's gotta be right.
Paul AsadoorianHOST
77:09
The first time now, can I help us? Sure.
Paul AsadoorianHOST
77:13
Um, is it great at being a hundred, helping us be a hundred percent accurate? Not necessarily, uh, And I think that's where we have a lot of work to do to enable AI for defenders to keep up with this onslaught, Jeff, right? This is the Patch Tuesday where I think we're really kind of feeling the...
Sam BownePANELIST
36:17
Then they just patched it again, and he did it again.
Sam BownePANELIST
36:19
Nope, your patch is still crap.
Sam BownePANELIST
36:21
And I think each time he waited until just after Patch Tuesday to do that.
Sam BownePANELIST
36:25
Yes,
Paul AsadoorianHOST
36:26
yes,

41 MINS LATER

Paul AsadoorianHOST
77:09
And it's gotta be right.
Paul AsadoorianHOST
77:09
The first time now, can I help us? Sure.
Paul AsadoorianHOST
77:13
Um, is it great at being a hundred, helping us be a hundred percent accurate? Not necessarily, uh, And I think that's where we have a lot of work to do to enable AI for defenders to keep up with this onslaught, Jeff, right? This is the Patch Tuesday where I think we're really kind of feeling the...
Dave BittnerHOST
2:49
It's great to have you with us.
Dave BittnerHOST
2:52
Microsoft's September Patch Tuesday is its largest on record, with the company reporting fixes for nine hundred and sixty-six vulnerabilities.
Dave BittnerHOST
3:02
Independent tallies vary slightly, but all point to an unusually heavy month.
Dave BittnerHOST
3:08
One hundred and five vulnerabilities are rated critical, two hundred and fifty-eight involve remote code execution, and four hundred and thirty-eight involve privilege escalation.
Leo LaporteHOST
27:50
[laughs]
Paul ThurrottHOST
27:51
Um, no. Um, but we did have Patch Tuesday, and I remember last week-
Leo LaporteHOST
27:56
Oh, my God, did we have a Patch Tuesday.
Paul ThurrottHOST
28:00
Yeah.
Leo LaporteHOST
28:00
Hoo.

9 MINS LATER

Paul ThurrottHOST
36:51
Um- Maybe they're just doing it for me to shut me the hell up, but, um, but either way I don't care.
Paul ThurrottHOST
36:56
It's fine.
Paul ThurrottHOST
36:57
Um, and then yesterday, which was Patch Tuesday, but ahead of the Patch Tuesday releases, Microsoft announced, you know, five Windows Insider builds because, you know, let's keep everyone busy.
James AzarHOST
0:00
Hey everyone, it's Patch Tuesday and Microsoft setting an all-time record nine hundred and seventy-four vulnerabilities, two already exploited in the wild.
James AzarHOST
0:07
FortiGate firewalls are actively compromised with a Node.js RAT that's decrypting your VPN credentials and exfiltrating Exchange mailboxes.
James AzarHOST
0:16
White Hat hackers draining three hundred and twenty million dollars from the Liquid Bitcoin network via a software bug.
James AzarHOST
1:08
It's September ninth, twenty twenty-six.
James AzarHOST
1:10
We've got 12 stories, and I wanna flag right away that today's lineup cuts across more than the usual vulnerability and kind of breach territory.
James AzarHOST
1:18
Yes, we have the biggest Patch Tuesday in Microsoft history.
James AzarHOST
1:23
Yes, we have an active FortiGate campaign hitting US organizations right now.
James AzarHOST
1:29
But we're also spending real time on a three hundred and twenty million dollar blockchain exploit and an AI credential theft campaign because both have business risk implications that practitioners need to be bringing into their executive team and boardroom, not just our SOC.
Alexandra MooreHOST
2:11
Sure.
John DilgenHOST
2:11
So this week, just yesterday on September 8th, Microsoft announced its largest Patch Tuesday ever, in which they released patches to fix over 950 vulnerabilities.
John DilgenHOST
2:25
Now, if you've been listening for a while, you know that we've warned about the number of vulnerabilities that will be discovered in the future and are currently being discovered by frontier AI models, which Microsoft is using their own version of.
John DilgenHOST
2:40
And you'll likely also remember our recent episode in July where we spoke about Microsoft's largest Patch Tuesday ever, and that was the largest one at the time.
John DilgenHOST
2:50
But back in July, they announced fixes for over 570 flaws, being the largest.
John DilgenHOST
2:56
Well, just yesterday they fixed over 950, a staggering increase in volume here.
John DilgenHOST
3:04
So Alex, I just wanna kick things off and open up a question to you, as we've talked about, do you think that the recent volume we've seen from these Patch Tuesdays is just organizations finding the low-hanging fruit vulnerabilities within their code, and as they're being fixed, and we'll, we'll turn back to a normal volume soon? Or do you think that this volume is gonna maintain itself and it's gonna become the new normal?
Alexandra MooreHOST
3:26
Ah, you're asking the, the tough questions to start the episode off, John.
Paul ThurrottHOST
27:52
No.
Paul ThurrottHOST
27:53
But we did have Patch Tuesday, and I remember last week.
Paul ThurrottHOST
27:57
Oh, my God.
Paul ThurrottHOST
27:58
Did we have a Patch Tuesday? Yeah.
Paul ThurrottHOST
28:01
Yeah, and honestly, from a new features perspective and from a security vulnerabilities fixed perspective, kind of one of the bigger ones, actually, in the latter case, by far the biggest one.
Paul ThurrottHOST
28:13
But this is the set of features that is sort of thought of as 26H2, even though these are coming today to 25 and 24H2 because that's how this works, right? Um, so I don't know, you know, if you have 26 H one, you got nothing.

8 MINS LATER

Paul ThurrottHOST
36:51
Um, maybe they're just doing it for me to shut me the hell up, but, um, but either way, I don't care.
Paul ThurrottHOST
36:56
It's fine.

22 more episodes mention Patch.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.