In a single update cycle, Microsoft has just addressed more vulnerabilities than most organisations would expect to see disclosed across an entire year.
July’s Patch Tuesday addressed 570 vulnerabilities, the largest release in the programme’s history and roughly three times the volume patched in June. Three zero-day vulnerabilities were included, two of which were already being actively exploited before a fix was available.
Taken together, these figures mark a meaningful shift in the pace at which vulnerabilities are being identified and disclosed, and organisations should treat this month’s release as an indicator of what is now the norm rather than an isolated event.
Microsoft has attributed the scale of this release to its expanded use of AI in vulnerability discovery. The system behind it, internally referred to as MDASH, uses multiple AI models and a large number of specialised agents to review Microsoft’s codebase in parallel, flag potential flaws, and cross-check findings before they reach engineering teams for remediation. It’s a more effective way of finding vulnerabilities that were already there, working at a scale manual review was never going to match.
Microsoft has said explicitly that customers should expect this volume to continue as the technology matures, and other major vendors are seeing similar increases as AI-assisted vulnerability discovery becomes part of standard practice.
What this shift means in practice
The number itself isn’t really the issue. What matters more is the direction it points in. Vulnerabilities are being found faster, in far greater volume, and Microsoft has separately noted that the window between a vulnerability being disclosed and an exploit appearing for it keeps getting shorter.
A pace built around periodic, manually-scheduled patch cycles was already a stretch in a slower-moving threat landscape. When the volume of disclosures and the speed of exploitation are both increasing, the time between a patch being released and it actually being applied becomes the main source of exposure. For capital markets, where availability and data integrity aren’t negotiable, that exposure carries real weight.
This isn’t a criticism of internal security teams. Reviewing, testing and deploying several hundred patches in one cycle, without disrupting production trading environments, is a lot to ask of any team on top of their existing workload.
How Beeks approaches security patching
This is precisely the problem our Managed Security Patching service exists to solve. Instead of periodic, manually-triggered patch cycles that leave infrastructure exposed for days or weeks after a fix is published, Beeks provides automated patching that identifies, tests and applies critical updates as soon as they’re released. Change is managed with the rigour production capital markets environments demand, but without the delay that comes from relying on manual scheduling.
As Microsoft and other major vendors move toward higher-frequency, AI-accelerated release cycles, that combination is what will separate organisations that stay ahead of exposure from those still catching up when the next record-breaking release lands. It’s also the reason we built Managed Security Patching as a standing service rather than a reactive one: the infrastructure best protected in July is the same infrastructure that will be best protected in whatever release follows it.
If this month’s numbers have prompted any second-guessing about how your own patch management would hold up under that kind of volume, it’s a good moment to have an internal review.
To discuss how automated patching can reduce your exposure window, speak with the Beeks team about our Managed Security Patching service here.






