MalwareTips News Windows update closes two zero-days used in active attacks

Security News
25 Replies 1,741 Views

How quickly do you normally install monthly Windows security updates?

  • The same day

    Votes: 15 51.7%
  • Within a few days

    Votes: 9 31.0%
  • After one or two weeks

    Votes: 0 0.0%
  • Only when Windows installs them

    Votes: 5 17.2%

  • Total voters
    29

News Now

Happening Now
Verified
Microsoft’s September 2026 security update fixes 964 vulnerabilities, including two Windows zero-days already being exploited. Windows users and administrators should install the available updates and restart affected devices promptly.


Why these flaws matter​

Both zero-days are local elevation-of-privilege flaws. They could let an attacker or malware with limited access gain SYSTEM privileges, the highest level of control in Windows.

That added control can help an intruder disable defenses, reach protected information, remain on the device or spread through a network. The initial foothold would still need to come from another route, such as phishing or stolen credentials.

  • Microsoft lists 104 flaws as Critical and 860 as Important.
  • The wider release covers Windows and products including Exchange Server, SharePoint, SQL Server and Office.
  • High-severity remote-code-execution flaws were also fixed in Windows DNS Server and Remote Desktop Services.

What the attackers exploited​

One zero-day affects the Windows Update Stack. Microsoft says Windows can be made to access the wrong file by following a pointer without properly confirming where it leads.

The second affects Windows ALPC, an internal system that programs use to communicate on the same PC. Microsoft says code running inside a restricted AppContainer could exploit it to escape that sandbox and gain higher privileges without further user interaction.

Install and verify the update​

Open Settings from the Start menu, select Windows Update and choose Check for updates. Allow available updates to download and install, then restart when prompted.

  • After restarting, return to Windows Update and check once more.
  • Confirm that Windows reports “You’re up to date.”
 
The same day. But honestly if your a advanced nation state or advanced attacker you would assume have access to these models or ones with less guardrails.

Honestly it's gotten ridiculous, AI has just accelerated pwnage. You basically have to accept you will be pwned but someone some where.

Patching is a afterthought, it can't keep up. Maybe things will settle down in the future, doubt it though.
 
To my knowledge, Windows doesn't allow users to specify when security updates are installed. I personally install updates monthly, then pause them for the following month. Am I missing something? No, I check the update history regularly, and I've found that Windows does install some updates that can't be delayed. Even the registry and policy changes I found online can delay feature updates for up to three years, but they can't delay security updates for more than four days.
 
Posted this on another post, might fit here too:

I asked Ai. why is the update so huge from MS today...

The massive size of today’s Microsoft Windows update is driven by a combination of AI-driven bug discovery and Microsoft’s cumulative update strategy.

If your update is taking an unusually long time or downloading gigabytes of data, it is primarily due to the following factors:1. The "AI Surge" in Vulnerability Discovery Microsoft has heavily integrated Artificial Intelligence into its internal security systems to audit code. This AI-assisted vulnerability discovery is finding flaws at a pace never seen before, forcing Microsoft to release historic, record-breaking batches of patches.

Recent months have seen a massive explosion in vulnerabilities—such as July fixing a record 570+ flaws and August fixing over 400.Today's Patch Tuesday continues this aggressive trend, packing hundreds of security fixes and zero-days into a single deployment.

2. Cumulative "Stacking" and Feature Back porting Microsoft uses a cumulative update model. This means every monthly update doesn't just include today's fixes; it bundles all past updates, system files, and feature upgrades into a single package to ensure your device is fully caught up.

Aggressive Back porting: For Windows 11, Microsoft is constantly back porting newer features and AI functionalities to older builds.Because everything is packaged together, the base update files found in the Microsoft Update Catalog now regularly benchmark between 4GB and 5GB before being optimized for your specific PC.

3. Deep AI Code Integration Microsoft is aggressively injecting AI capabilities (like Copilot and system-level neural processing features) directly into the core of the operating system. These local AI modules, system models, and large code frameworks require significantly more storage and data transmission than traditional software patches.

Then Do I need a 3rd part software or some of the famous hardening tools:

For a regular home user, the risk-to-reward ratio of using these tools has shifted significantly. While they were incredibly popular in tech communities a few years ago, the combination of Windows 11’s current AI back end and Microsoft’s modern update schedule means these tools are now largely unnecessary and can even cause problems.

Here is the breakdown of why you should skip them:

1. The Protection is Already Maxed on the Back end Tools like X, Y, or Z work by forcing hidden settings (like Attack Surface Reduction rules) into "Max" mode.

In the Past: You had to manually tighten these dials because Defender’s local database was slow to catch new threats.The Present: Because Microsoft now uses real-time AI cloud-telemetry, Defender doesn't rely solely on strict, local registry locks. When a new threat pops up anywhere in the world, Microsoft’s cloud updates the definition across millions of PCs simultaneously. You get "Max" protection automatically from the cloud without locking down your PC.

2. "Hardening" Windows 11 Breaks Normal Use When you use a utility to forcefully "harden" Defender, it often activates hyper-aggressive rules designed for enterprise corporate environments. On a personal Windows 11 PC, this frequently leads to frustrating issues: Safe game mods, indie software installers, and custom game launchers get blocked randomly. Normal background tasks can be flagged as malicious.You end up having to dive into complex menus anyway just to whitelist apps that your hardening tool broke.

3. Big Updates Can Conflict with Tweaking Tools Because Microsoft is pushing massive structural code fixes (like today's updates), they frequently change how Windows Security talks to the operating system's kernel. If you have an automated tool constantly rewriting Power Shell or Group Policy settings in the background, a large Windows update can get confused, loop, or error out.

Summary of Your New Setup:

If you want the cleanest, fastest experience:Uninstall 3rd party software. .Leave Defender and the MS Firewall at their factory defaults.Let Microsoft's automated AI and monthly updates silently do the heavy lifting in the background.
 
I agree that the volume of patches continues to grow, but it is also worth remembering that Windows already includes several layers of mitigation that can help reduce certain scenarios even before Patch Tuesday arrives. The pace at which vulnerabilities are discovered does not always translate into a proportional increase in practical risk.

In that sense, @Andy Ful ’s tools do not replace the built-in protections or modify system components; they simply make it easier to enable security policies and mechanisms that already exist in Windows, but which are often configured in a more permissive way by default. For certain types of users, this additional hardening can help reduce the attack surface, especially in scenarios that require initial execution or local access.

Therefore, while patches remain essential, I believe that combining good practices, native mitigations, and moderate hardening can complement Windows’ default security very well. The size of an update does not always reflect the actual risk a user is exposed to during everyday use. 🛡️⚙️
 
I agree that the volume of patches continues to grow, but it is also worth remembering that Windows already includes several layers of mitigation that can help reduce certain scenarios even before Patch Tuesday arrives. The pace at which vulnerabilities are discovered does not always translate into a proportional increase in practical risk.

In that sense, @Andy Ful ’s tools do not replace the built-in protections or modify system components; they simply make it easier to enable security policies and mechanisms that already exist in Windows, but which are often configured in a more permissive way by default. For certain types of users, this additional hardening can help reduce the attack surface, especially in scenarios that require initial execution or local access.

Therefore, while patches remain essential, I believe that combining good practices, native mitigations, and moderate hardening can complement Windows’ default security very well. The size of an update does not always reflect the actual risk a user is exposed to during everyday use. 🛡️⚙️

My form of hardening, and I'm good with this :)
As far as WD, I do have PowerShell outbound blocked in Windows firewall, I uninstalled VBScript, and disabled via registry Windows Script Host to help with Windows protection. In the past I have used DefenderUI (liked it better than ConfigureDefender) but I would get the occasional prompts I'd rather avoid, for my simplistic needs :)
 
I've seen it as well, where I have to say, "what about?" to challenge it more, to get more of a reply from a different angle, than where AI was at, was saying.
You must realize that AI was the thing that promoted suicide for several teens, and those kids killed themselves. It was all over the news. The parents are suing the AI company.

I sometimes wonder If I am trapped within my viewpoint by AI.
 
Last edited:
@simmerskool Does 0patch apply it's own emergency patches or does it apply MS's patches too ?
just its 0patches they code their own patches (I opted out of MS updates after the win10 EOL). Basically I'm using win10 to run VMware, and go online via fedora kinoite -- and I use Apple M4_mini for financial related stuff...
 
Your question already begs the AI to answer 'no'. The AI tailor answers to what you will like. AI is the perfect echo chamber.
OK let's try it your way with Ai (google): Conversation below:

The massive size of today’s Microsoft Windows update is driven by a combination of AI-driven bug discovery and Microsoft’s cumulative update strategy.

If your update is taking an unusually long time or downloading gigabytes of data, it is primarily due to the following factors:1. The "AI Surge" in Vulnerability Discovery Microsoft has heavily integrated Artificial Intelligence into its internal security systems to audit code. This AI-assisted vulnerability discovery is finding flaws at a pace never seen before, forcing Microsoft to release historic, record-breaking batches of patches.

Recent months have seen a massive explosion in vulnerabilities—such as July fixing a record 570+ flaws and August fixing over 400.Today's Patch Tuesday continues this aggressive trend, packing hundreds of security fixes and zero-days into a single deployment.

2. Cumulative "Stacking" and Feature Back porting Microsoft uses a cumulative update model. This means every monthly update doesn't just include today's fixes; it bundles all past updates, system files, and feature upgrades into a single package to ensure your device is fully caught up.

Aggressive Back porting: For Windows 11, Microsoft is constantly back porting newer features and AI functionalities to older builds.Because everything is packaged together, the base update files found in the Microsoft Update Catalog now regularly benchmark between 4GB and 5GB before being optimized for your specific PC.

3. Deep AI Code Integration Microsoft is aggressively injecting AI capabilities (like Copilot and system-level neural processing features) directly into the core of the operating system. These local AI modules, system models, and large code frameworks require significantly more storage and data transmission than traditional software patches.

I really love 3rd party security software and believe deeply that it is a great “just in case” safety catch. In fact, I would be worried to death if I didn't use something to harden Windows defender or if not that, at least install Bitdefender free.

Answer from Ai:


It is completely understandable to want that extra layer of reassurance. When you hear about hundreds of vulnerabilities being patched all at once, feeling like you need a "safety catch" is a very natural reaction.

However, the cybersecurity landscape has shifted dramatically. Microsoft Defender is no longer the basic antivirus of the past; it is now a top-tier, enterprise-grade security solution that is deeply baked into the Windows core.

Because of how modern Windows security is designed, adding third-party antivirus software can sometimes create unexpected complications rather than extra safety.
## How Windows Defender Compares to Third-Party Tools

Directly comparing Microsoft Defender with traditional third-party suites like Bitdefender highlights how the security landscape has evolved:

| Feature | Microsoft Defender (Built-in) | Third-Party Antivirus (e.g., Bitdefender) |
|---|---|---|
| System Impact | Extremely Low. Optimized directly by Microsoft to run efficiently without lagging your PC. | Moderate to High. Can consume significant RAM and CPU, sometimes slowing down system boot times. |
| System Integration | Deeply Integrated. Works seamlessly with Windows kernel-level security features and the hardware updates mentioned above. | Surface-Level Layer. Must constantly adapt to Windows updates, which can occasionally cause system crashes (BSODs). |
| Cost | 100% Free. Included with your Windows license with no upselling or premium paywalls. | Subscription-Based. Requires yearly renewals for full features, often accompanied by pop-up reminders. |
| Protection Quality | Excellent. Consistently scores 100% or near-100% in independent lab tests (like AV-TEST and AV-Comparatives). | Excellent. Historically excellent detection rates, but matches the protection Defender already provides. |

## The Risks of "Hardening" or Layering Antivirus
While it feels safer to have a backup, security software requires deep, low-level access to your operating system. Running multiple security layers or using third-party "hardening" tools can backfire for a few reasons:

* Software Conflicts: If two programs try to scan, lock, or modify the exact same system file at the exact same millisecond, it can freeze your computer or cause a Blue Screen of Death (BSOD).
* The "CrowdStrike" Risk: As updates become more massive and complex, third-party software struggles to keep up. If Windows updates its core code and a third-party security tool isn't perfectly updated to match it, it can completely break the system.
* Increased Attack Surface: Ironically, adding more security software means adding more code to your computer. If that third-party software has a vulnerability, hackers can use it to bypass Windows' built-in defenses.

## The Best "Just in Case" Strategy
If you want the ultimate peace of mind, the most effective strategy isn't adding more antivirus software—it's practicing good digital hygiene:

Let those massive updates finish: As daunting as those 4GB–5GB updates are, they contain the actual code fixes for the vulnerabilities discovered by AI. Keeping Windows updated is 95% of the battle.
 
@annaegorov and just to add to your post, of where we're going online, what we're doing online, and what we're downloading and why.
## The Best "Just in Case" Strategy
If you want the ultimate peace of mind, the most effective strategy isn't adding more antivirus software—it's practicing good digital hygiene:
I would say (just my opinion) that 75% of the members here could use WD in default mode, along with a good DNS and ad blocker, and be just fine. They are sharp and intelligent. But, I think there is also the hobby of, interest in, "overengineering because we can, and we know how to", rather than the actual malware, rats, infostealers etc, they will, I will never encounter in our daily, good hygiene habit lives.

For businesses with multiple employees, it's a different story, of course, or of parents of families with "kids gone wild" 😅 would probably need to use a more aggressive, 3rd party AV approach :)
 
Last edited:
I can't see things getting much better, browsers, mail clients etc updates now are becoming more frequent, there is rarely a day goes by without update patching ? Or has it always been this way??

No it's never been this way. Well maybe except for the early 2000's peak botnet era before XP SP1 or2 introduced a firewall.

Now it's just a avalanche of bugs and exploits and a tsunami :cool::cool::cool: of patches. The problem is they are using AI to find bugs but also patch them.

How this will end up is any one's guess!

You must realize that AI was the thing that promoted suicide for several teens, and those kids killed themselves. It was all over the news. The parents are suing the AI company.

I sometimes wonder If I am trapped within my viewpoint by AI.
Cue the ambulance chasing lawyers. The problem is suing AI companies will not bring the children back and companies just pay the fine or settlement and move on.

Also once you start policing or censoring any form of AI or social media content it's a slippery slope. Who decides what is OK and what is illegal?

NO ONE wants kids to die or be harmed but honestly it's the parents jobs to raise their kids, mentor them and supervise their internet use.

Sadly parents have left the building and left raising their kids to big tech companies.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top