[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-microsoft-974-bugs-ai-haystack":3,"topics-all":35,"news-related-e61b1180-f540-4ec5-9796-b24d9258d2ca":54},{"id":4,"title":5,"summary":6,"content":7,"original_url":8,"source_id":9,"tags":10,"translations":21,"news_slug":28,"published_at":29,"created_at":30,"modified_at":31,"is_published":32,"publish_type":33,"image_url":14,"view_count":34},"e61b1180-f540-4ec5-9796-b24d9258d2ca","AI 辅助挖洞时代的补丁爆炸:微软单月修复 974 个 bug,专家却说「针没变多」","微软 9 月例行更新一次修了 974 个漏洞,刷新单月纪录。AI 辅助漏洞发现被认为是补丁数飙升的关键原因之一,但 Tenable 工程师指出,真正能影响多数组织的关键漏洞数量并未同步增加——AI 让干草堆变大,但针没变多。","从 7 月的 570 个,到 9 月的 974 个,微软 Patch Tuesday 的月度修复数用三个月完成了一次台阶式跳涨。截至 9 月这次发布,2026 年的累计补丁数已突破 2600,远超 2020 年全年 1245 个的旧纪录,而年内还有三个月没走完。\n\n## 9 月这一批里最危险的是什么\n\n974 个补丁里有 113 个被微软评为「严重」(critical),两个零日漏洞 CVE-2026-81963 和 CVE-2026-85880 已被发现在野利用,都和权限提升有关。最值得单拎出来的是 CVE-2026-69730,一个影响 Windows Server 2012 及以后版本、Windows 10 也躺枪的 DNS 缺陷:未认证攻击者只要向目标发一个精心构造的数据包就能触发。另一个 CVE-2026-69829 是 Windows Shell 的远程代码执行漏洞,CVSS 基础评分 9.8,攻击复杂度低、无需权限、无需用户交互。\n\n## AI 是不是补丁变多的「功臣」\n\n微软在公告里明确表示 AI 加速了漏洞发现。Krebs on Security 在报道中做了一个关键的横向对比:Adobe、Cisco、Google、Mozilla、Oracle 也都在最近把补丁节奏和体量增长归因于 AI 辅助研究——Google 本周刚刚宣布把 Chrome 安全更新改为每两周一次。\n\n但 Tenable 高级研究工程师 Satnam Narang 给出了不同的判断:「AI 辅助漏洞发现在 2026 年创造了一个更大的干草堆,但并没有找到更多针。」他的意思是,绝大多数被发现的 CVE 对绝大多数组织其实不可达、不可利用;CISO 真正该做的是按可达性和可利用性排序,而不是被每月一千条的更新数量压垮。\n\n## 企业 IT 团队已经扛不住了\n\nFortra 安全研究副总监 Tyler Reguly 直接把话挑明:「是时候把 CISOs 和 CSOs 叫到一起了。你们的预算能买多少顿周六加班的晚餐?」他的意思是,企业内部测试和部署补丁的运维团队正在被月度补丁轰炸拖垮。\n\n这并不是微软一家的问题——同月 Adobe、Cisco、Oracle 都发布了巨型补丁包。每个月多几百条 CVE 听起来像是安全研究在进步,但当维护者每周都要处理几百条 PR、Linux 内核维护者已经被 AI 工具挖出的「接近 2000 个 CVE」压到需要主动删旧驱动才能维持节奏,这场胜利越来越像一场苦胜。\n\n## 所以呢\n\nAI 把漏洞发现的门槛降到了「每月扫一遍」级别,但企业侧的修复能力并没有同步增长。当补丁数从 1245 跳到 2600+,真正受益的不是攻击者(他们早就有 N-day 工具链),而是先在野利用的零日攻击——这两条曲线之间的差距,就是 2026 年企业安全的真正成本。\n\n参考来源:Krebs on Security,《Microsoft Plugs Nearly 1,000 Security Holes》(https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F09\u002Fmicrosoft-plugs-nearly-1000-security-holes\u002F)。","https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F09\u002Fmicrosoft-plugs-nearly-1000-security-holes\u002F","b1108f02-1cb8-49c3-a96d-171bb875a099",[11,15,18],{"id":12,"name":13,"slug":13,"description":14,"color":14},"5e628969-6d2a-437f-998a-104e4b16cfb1","ai-progress",null,{"id":16,"name":17,"slug":17,"description":14,"color":14},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",{"id":19,"name":20,"slug":20,"description":14,"color":14},"40269b40-7942-4650-9672-ed2e6524d37a","ai-technology",[22],{"id":23,"lang":24,"title":25,"summary":26,"content":27},"3ad7d8c4-e27b-4b2a-8280-7827099c6262","en","Microsoft's 974-Bug Patch Tuesday: AI Finds Haystacks, Not Needles","Microsoft's September Patch Tuesday fixed 974 vulnerabilities, a record. A Tenable analyst argues AI-assisted discovery inflates the haystack, not the needle","From 570 bugs in July to 974 in September, Microsoft's Patch Tuesday delivered a step-jump in monthly fixes over just three months. With this September release, the 2026 cumulative patch count has crossed 2,600—already more than double the previous full-year record of 1,245 set in 2020—and three months remain on the calendar.\n\n## What Is Actually Dangerous in This Batch\n\nOf the 974 patches, 113 carry Microsoft's \"critical\" rating. Two zero-day vulnerabilities—CVE-2026-81963 and CVE-2026-85880—are being actively exploited in the wild, both tied to privilege escalation. The one worth singling out is CVE-2026-69730, a DNS flaw affecting Windows Server 2012 onward as well as Windows 10: an unauthenticated attacker can trigger it by sending a single crafted packet. The other is CVE-2026-69829, a Windows Shell remote code execution bug with a CVSS base score of 9.8—low attack complexity, no privileges required, no user interaction needed.\n\n## Is AI the Reason Behind the Patch Flood\n\nMicrosoft stated in its advisory that AI is accelerating vulnerability discovery. Krebs on Security's reporting draws an important cross-vendor comparison: Adobe, Cisco, Google, Mozilla, and Oracle have all recently attributed faster patch cadence and bigger bundle sizes to AI-assisted research—Google this week even announced that Chrome security updates will now ship every two weeks.\n\nBut Satnam Narang, senior staff research engineer at Tenable, offers a different read: \"AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn't finding more needles.\" His point: most CVEs being discovered are not actually reachable or exploitable for most organizations. The CISO's real job is to prioritize based on reachability and exploitability, not to be crushed by a thousand-line monthly bulletin.\n\n## Enterprise IT Teams Are Already Drowning\n\nTyler Reguly, associate director of security research and development at Fortra, put it bluntly: \"It's time to put our CISOs and CSOs on notice. How much can your budget buy in Saturday-night pizza?\" His meaning: the operations teams inside enterprises who test and deploy patches are being worn down by the monthly patch flood.\n\nThis isn't Microsoft's problem alone—Adobe, Cisco, and Oracle released giant patch bundles the same month. A few hundred extra CVEs per month sounds like progress in security research, but when maintainers have to handle hundreds of PRs each week, and Linux kernel maintainers are being squeezed by \"close to 2,000 CVEs\" surfaced by AI tools to the point of actively deleting legacy drivers just to keep pace, this victory increasingly looks like a pyrrhic one.\n\n## So What\n\nAI has lowered vulnerability discovery to a \"scan-everything-monthly\" level, but enterprise-side remediation capacity hasn't grown in step. When patch counts jump from 1,245 to over 2,600, the real beneficiaries aren't attackers (who already have N-day toolchains) but zero-day exploits that fire first—the gap between those two curves is the true cost of enterprise security in 2026.\n\nReference: Krebs on Security, \"Microsoft Plugs Nearly 1,000 Security Holes\" (https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F09\u002Fmicrosoft-plugs-nearly-1000-security-holes\u002F).","microsoft-974-bugs-ai-haystack","2026-09-11T04:00:00Z","2026-09-11T05:09:00.038281Z","2026-09-11T05:09:00.038290Z",true,"agent",72,[36,45],{"slug":37,"tag_slug":37,"title_zh":38,"title_en":39,"intro_zh":40,"intro_en":41,"id":42,"is_active":32,"created_at":43,"modified_at":44},"ai-for-science","AI for Science 2026：从 UniPert 到 GPT-Rosalind 的硬核进化","AI for Science 2026: from UniPert to GPT-Rosalind","生命科学、化学材料、物理世界模型——AI 正在从\"语言工具\"变成\"实验伙伴\"。本专题收录 AI 在三大科学方向的关键节点：UniPert 统一基因与化学扰动空间、GPT-Rosalind 端到端生命科学推理、达摩院 AI 智能体 28 小时找到 4 种超导新材料、Anthropic Claude Science 把工作台做成标准品。","From language tool to lab partner — AI is reshaping life sciences, chemistry\u002Fmaterials, and physical world models. This topic covers the key milestones: UniPert unifying genetic-chemical perturbation spaces, GPT-Rosalind's end-to-end life-sciences reasoning, DAMO's AI agent discovering 4 superconducting materials in 28 hours, and Anthropic's Claude Science workbench going mainstream.","988a4300-5fab-41c4-b5d8-63711a2dc757","2026-09-10T01:34:15.296649Z","2026-09-10T01:34:15.296663Z",{"slug":46,"tag_slug":46,"title_zh":47,"title_en":48,"intro_zh":49,"intro_en":50,"id":51,"is_active":32,"created_at":52,"modified_at":53},"h3-series","MiniMax H3 系列：从开源权重到 35 倍吞吐","MiniMax H3 Series: from open weights to 35x throughput","MiniMax H3 自 2026 年 8 月开源以来节奏密集：官方把生成、参考与编辑收回一个模型；ComfyUI 当天压进 RTX 3060；摩尔线程 3 小时完成国产 GPU 适配；fal 后训练版把吞吐拉到 35 倍；FastH3 蒸馏再砍推理成本。本专题持续追踪 H3 的发布—开源—蒸馏—部署全链路。","Since MiniMax open-sourced H3 in August 2026 the pace has been relentless: one unified omni-modal model, same-day ComfyUI support down to an RTX 3060, a 3-hour Day-0 port to Moore Threads GPUs, fal's post-trained H3 Max at 35x throughput, and FastH3 distillation cutting inference cost further. This topic tracks the full H3 chain — release, open weights, distillation, deployment.","83ef0daa-3c31-4cb3-86ed-e5ee58654d5f","2026-09-08T07:33:19.942193Z","2026-09-08T07:33:19.942209Z",{"items":55},[56,61,66,71,76,81],{"id":57,"title":58,"news_slug":59,"published_at":60},"e73fe0e6-1b5a-46a2-bbfb-d9a2f1f065d7","AI 智能体挖遍代码库:隐晦式安全在 Patch Tuesday 974 个 CVE 面前失守","ai-agents-kill-security-obscurity","2026-09-15T01:06:05+00:00",{"id":62,"title":63,"news_slug":64,"published_at":65},"cb7fb8b3-5862-4cba-adab-c4794e989966","图灵奖得主 Pearl 长访谈：LLM 能讲因果只是因为人类替它爬过了因果阶梯","judah-pearl-llm-causal-ladder-agi","2026-07-31T07:00:00+00:00",{"id":67,"title":68,"news_slug":69,"published_at":70},"8a1c0216-5fd5-4b49-8e5b-955625401f05","Microsoft HARC 把 LLM 安全对齐锁进「有害性-拒答」二维子空间:在残差流里精准打补丁","microsoft-harc-safety-alignment","2026-07-16T10:14:00+00:00",{"id":72,"title":73,"news_slug":74,"published_at":75},"1426518b-daf6-4833-9a7e-294be91d8714","FARMA 把伪造推理塞进 Agent 记忆:LLM 持久记忆的完整性危机","farma-fake-reasoning-memory","2026-07-11T02:30:00+00:00",{"id":77,"title":78,"news_slug":79,"published_at":80},"7bab0122-cbc7-45ae-b99e-b3b4a056fd04","LMLM「遗忘审计」撕开 RAG 删除幻觉:未学≠真正删除,残留最高 13.6%","lmlm-rag-deletion-audit","2026-07-06T12:15:00+00:00",{"id":82,"title":83,"news_slug":84,"published_at":85},"b398dc77-58a1-498e-a9ed-c045c83c90be","AI 抢走消费级 DRAM:一年涨价五倍,手机路由器全被拖下水","ai-dram-consumer-electronics-price-surge","2026-09-14T01:00:00+00:00"]