为什么微软“补丁星期二”更新突然包含如此多的修复

内容总结:
微软周二发布八月安全更新,修复了多达400个漏洞,其中包括三个已被积极利用或公开披露的零日漏洞,数量创下新高。这是继此前数月连续打破纪录后,微软再次大幅增加补丁规模,凸显出网络安全形势正因人工智能技术的介入而急剧变化。
安全专家指出,AI正在“攻防两端”同时发挥作用。一方面,网络攻击者利用AI快速开发和部署攻击工具,使得漏洞被利用的门槛降低、速度加快,迫使科技公司不得不打破常规更新节奏,紧急修补漏洞。今年夏天,苹果公司就曾因此缩短更新周期。另一方面,AI也在帮助防御方更快发现隐患。微软上个月透露,借助AI,其工程团队能在漏洞被利用前发现并分析更多潜在缺陷,这也是补丁数量激增的直接原因。谷歌同样利用AI在Chrome浏览器中寻找、分类并修复安全漏洞。不过,当前AI在定位漏洞方面表现突出,但在实际修复漏洞上效率有限,甚至可能引入新问题。
对于普通Windows用户而言,最有效的防护仍是第一时间安装更新。补丁一般于每月第二个周二上午10点左右自动推送,用户也可通过“开始—设置—Windows更新—检查更新”手动确认。据BleepingComputer报道,此次八月更新修复的漏洞覆盖多个类别,包括176个权限提升漏洞、11个安全功能绕过漏洞、110个远程代码执行漏洞、86个信息泄露漏洞、21个欺骗漏洞及12个拒绝服务漏洞,其中42个被评为“严重”,主要涉及远程代码执行和权限提升。
中文翻译:
如果你是Windows用户,希望你已安装了微软每月定期发布的“补丁星期二”更新,这些更新旨在修复公司软件中存在的关键安全漏洞。最近几个月的修复尤其重要,因为它们包含了创纪录数量的漏洞以及一大批已被积极利用或公开披露的零日漏洞。
本周发布的八月“补丁星期二”也不例外:该更新修复了400个漏洞,其中包括三个零日漏洞。相比之下,三月份微软仅为83个漏洞发布了补丁(其中两个是公开披露的零日漏洞)。漏洞和安全修复数量看似突然激增,很大程度上归因于人工智能。
人工智能正在制造漏洞(也在发现漏洞)
在安全领域,人工智能扮演着双重角色。威胁行为者正在利用AI更快、更大规模地开发和部署黑客工具,因此更多漏洞可能比以前更容易被利用。这迫使科技公司也必须更快地做出响应。正如ZDNET所指出的,在常规更新周期(如“补丁星期二”)中修补漏洞的公司,如今不得不更早地匆忙修复问题,并可能开始缩短更新间隔,就像苹果今年夏初所做的那样。
虽然AI正在帮助利用漏洞,但它也在发现漏洞以便修复。上个月,微软宣布AI使其工程团队能够在漏洞被利用之前发现并分析更大数量的潜在缺陷。(该公司指出,这也直接促成了“补丁星期二”中安全更新数量的增加)。谷歌也在利用AI发现、分类并修复Chrome浏览器中的安全漏洞。值得注意的是,虽然AI擅长识别漏洞,但在实际修补漏洞方面效果远没有那么好——而且过程中还可能引入更多问题。
一如既往:尽快更新你的Windows设备
Windows用户应确保在安全更新可用后立即安装,以将主动攻击的风险降至最低。“补丁星期二”于每月第二个星期二上午10点左右发布,你应能自动收到更新。不过,你也可以通过“开始”>“设置”>“Windows更新”>“检查Windows更新”来查看状态。
据BleepingComputer报道,八月份的安全更新修复了以下类别的漏洞:176个权限提升漏洞、11个安全功能绕过漏洞、110个远程代码执行漏洞、86个信息泄露漏洞、21个欺骗漏洞以及12个拒绝服务漏洞。其中42个漏洞被评定为“严重”,包括远程代码执行和权限提升类漏洞。
英文来源:
If you're a Windows user, you've hopefully installed regular Patch Tuesday updates from Microsoft, which address critical security vulnerabilities across the company's software. The last few months' worth of fixes have been especially important, as they've included a record number of bugs and a swath of zero-days that have been actively exploited or publicly disclosed.
The August Patch Tuesday release this week is no different: The update fixes 400 flaws, including three zero-days. Compare that to March, when Microsoft issued patches for just 83 bugs in total (two of which were publicly disclosed zero-days). The seemingly sudden uptick in vulnerabilities and security fixes is due, in large part, to AI.
AI is creating vulnerabilities (and discovering them)
AI is playing both sides of the field when it comes to security. Threat actors are using AI to develop and deploy hacking tools more quickly and at scale, so more flaws may be more exploitable than before. This forces tech companies to respond more quickly as well. As ZDNET notes, companies that patch vulnerabilities during regular update cycles (like Patch Tuesday) now have to rush to address bugs sooner and may begin to shorten the time between updates, as Apple did earlier this summer.
While AI is helping to exploit vulnerabilities, it is also finding them so they can be fixed. Last month, Microsoft announced that AI has allowed its engineering teams to find and analyze a larger volume of potential flaws before they can be exploited. (The company noted that this also directly contributes to the increase in security updates included in Patch Tuesday). Google, too, is using AI to discover, triage, and fix security flaws in Chrome. It's worth noting that while AI is good at identifying vulnerabilities, it is far less effective at actually patching them—and may introduce more bugs along the way.
As always, update your Windows device ASAP
Windows users should ensure security updates are installed as soon as they're available to minimize the risk of active exploits. Patch Tuesday is released around 10 a.m. on the second Tuesday of the month, and you should receive them automatically. However, you can check the status under Start > Settings > Windows Update > Check for Windows updates.
As BleepingComputer reports, the August security update addresses flaws across the following categories: 176 elevation-of-privilege vulnerabilities, 11 security feature bypass vulnerabilities, 110 remote-code-execution vulnerabilities, 86 information disclosure vulnerabilities, 21 spoofing vulnerabilities, and 12 denial-of-service vulnerabilities. Forty-two of the bugs are rated "critical" and include remote code execution and elevation of privilege flaws.
文章标题:为什么微软“补丁星期二”更新突然包含如此多的修复
文章链接:https://news.qimuai.cn/?post=4789
本站文章均为原创,未经授权请勿用于任何商业用途